Red Hat Jboss Enterprise Application Platform 8.1 For Rhel 8
21 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Red Hat Jboss Enterprise Application Platform 8.1 For Rhel 8. Use it to gauge the current risk picture and drill into individual advisories.
Red Hat Jboss Enterprise Application Platform 8.1 For Rhel 8 CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 1 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 1 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 1 |
| 2026-01 | 1 |
| 2026-02 | 0 |
| 2026-03 | 3 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 1 |
| 2026-08 | 10 |
| 2026-09 | 3 |
Severity
How the 21 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical1
- High16
- Medium4
Latest CVEs
The 15 most recently published vulnerabilities affecting Red Hat Jboss Enterprise Application Platform 8.1 For Rhel 8.
- CVE-2026-85511Wildfly-elytron-realm-token: parameter injection in eap's elytron oauth24.2
- CVE-2026-10832Org.wildfly.security/wildfly-elytron-asn1: unbounded memory allocation in wildfly elytron asn.1 derdecoder via crafted der payload5.9
- CVE-2026-86404Artemis-server: artemis-jms-client: artemis-core-client: undertow-core: wildfly-messaging-activemq-subsystem: artemis messaging handlers in red hat eap permit deserialization by default8.8
- CVE-2026-5680Undertow-core: undertow: denial of service via websocket permessage-deflate processing7.5
- CVE-2026-14180Undertow-core: undertow:http request smuggling via oversized chunk-size bit overlap5.3
- CVE-2026-15567Wildfly: wildfly-iiop: wildfly-jacorb: wildfly: pre-auth denial of service on the iiop listener7.5
- CVE-2026-15565Undertow: undertow-websockets: undertow: pre-auth dos on websocket endpoint with @serverendpoint class with any @onmessage method7.5
- CVE-2026-15563Wildfly-iiop-openjdk: missing authentication on eap's iiop nameservice leads to mitm or dos7.4
- CVE-2026-15562Jboss-remoting: jboss-remoting: integer overflow in messagereader leads to pre-authentication denial of service7.5
- CVE-2026-15561Undertow-core: oom via missing limits in chunked trailer in eap's undertow7.5
- CVE-2026-15560Openjdk-orb: unauthed class loading via iiop in eap8.1
- CVE-2026-15554Undertow-core: undertow: authentication bypass via ajp ssl_cert/is_ssl forgery7.4
- CVE-2026-15555Jboss-marshalling-river: wildfly-clustering-infinispan-marshalling: jboss deserialization rce via unfiltered river unmarshaller8.8
- CVE-2025-12799Jastow: jastow cross-site scripting attack due to unsanitized uri6.5
- CVE-2026-28367Undertow: undertow: request smuggling via `\r\r\r` as a header block terminator8.7
Product grouping is registry-driven, with AI assist and human review. How it works