CVE Tools

Red Hat Jboss Enterprise Application Platform 8.1 For Rhel 9

21 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Red Hat Jboss Enterprise Application Platform 8.1 For Rhel 9. Use it to gauge the current risk picture and drill into individual advisories.

Red Hat Jboss Enterprise Application Platform 8.1 For Rhel 9 CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Red Hat Jboss Enterprise Application Platform 8.1 For Rhel 9 CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-031
2025-040
2025-050
2025-060
2025-070
2025-080
2025-091
2025-100
2025-110
2025-121
2026-011
2026-020
2026-033
2026-040
2026-050
2026-060
2026-071
2026-0810
2026-093

Severity

How the 21 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical15%
  • High1676%
  • Medium419%

Latest CVEs

The 15 most recently published vulnerabilities affecting Red Hat Jboss Enterprise Application Platform 8.1 For Rhel 9.

  1. CVE-2026-85511Wildfly-elytron-realm-token: parameter injection in eap's elytron oauth24.2
  2. CVE-2026-10832Org.wildfly.security/wildfly-elytron-asn1: unbounded memory allocation in wildfly elytron asn.1 derdecoder via crafted der payload5.9
  3. CVE-2026-86404Artemis-server: artemis-jms-client: artemis-core-client: undertow-core: wildfly-messaging-activemq-subsystem: artemis messaging handlers in red hat eap permit deserialization by default8.8
  4. CVE-2026-5680Undertow-core: undertow: denial of service via websocket permessage-deflate processing7.5
  5. CVE-2026-14180Undertow-core: undertow:http request smuggling via oversized chunk-size bit overlap5.3
  6. CVE-2026-15567Wildfly: wildfly-iiop: wildfly-jacorb: wildfly: pre-auth denial of service on the iiop listener7.5
  7. CVE-2026-15565Undertow: undertow-websockets: undertow: pre-auth dos on websocket endpoint with @serverendpoint class with any @onmessage method7.5
  8. CVE-2026-15563Wildfly-iiop-openjdk: missing authentication on eap's iiop nameservice leads to mitm or dos7.4
  9. CVE-2026-15562Jboss-remoting: jboss-remoting: integer overflow in messagereader leads to pre-authentication denial of service7.5
  10. CVE-2026-15561Undertow-core: oom via missing limits in chunked trailer in eap's undertow7.5
  11. CVE-2026-15560Openjdk-orb: unauthed class loading via iiop in eap8.1
  12. CVE-2026-15554Undertow-core: undertow: authentication bypass via ajp ssl_cert/is_ssl forgery7.4
  13. CVE-2026-15555Jboss-marshalling-river: wildfly-clustering-infinispan-marshalling: jboss deserialization rce via unfiltered river unmarshaller8.8
  14. CVE-2025-12799Jastow: jastow cross-site scripting attack due to unsanitized uri6.5
  15. CVE-2026-28367Undertow: undertow: request smuggling via `\r\r\r` as a header block terminator8.7

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store