Impact
Undertow, the web server underlying JBoss EAP and WildFly, contains a flaw where WebSocket connection limits such as message buffer sizes and session timeouts are set to unlimited by default. An attacker can exploit this by sending large payloads or keeping connections open for extended periods, which can exhaust server memory or other resources and lead to service unavailability. The weakness is characterized as Unrestricted Resource Consumption (CWE-770).
Affected Systems
The vulnerability affects Red Hat’s Red Hat Enterprise Linux 10, 8, and 9 systems, as well as Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7 and 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Single Sign‑On 7, and Red Hat build of Apache Camel for Spring Boot 4. All these products rely on the underlying Undertow core which implements the WebSocket container with the problematic defaults. No specific affected version information is provided in the CVE data.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, while the EPSS score is not available, so the current likelihood of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote network access to a WebSocket endpoint; an attacker can initiate a connection and send large payloads or maintain the connection to trigger resource exhaustion. No official workaround is available, and the CNA indicates that the attack threat is not mitigated by existing options.
OpenCVE Enrichment