CVE Tools

Red Hat Jboss Enterprise Application Platform Expansion Pack

151 CVEs tracked. 1 of them are in CISA KEV.

This hub aggregates every CVE we track for Red Hat Jboss Enterprise Application Platform Expansion Pack, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.

Red Hat Jboss Enterprise Application Platform Expansion Pack CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Red Hat Jboss Enterprise Application Platform Expansion Pack CVEs per month
MonthCVEs
2024-103
2024-112
2024-122
2025-016
2025-021
2025-032
2025-041
2025-050
2025-061
2025-071
2025-080
2025-092
2025-100
2025-110
2025-121
2026-018
2026-023
2026-039
2026-041
2026-050
2026-065
2026-0728
2026-0834
2026-097

Severity

How the 151 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical43%
  • High5335%
  • Medium8355%
  • Low117%

Latest CVEs

The 15 most recently published vulnerabilities affecting Red Hat Jboss Enterprise Application Platform Expansion Pack.

  1. CVE-2026-85511Wildfly-elytron-realm-token: parameter injection in eap's elytron oauth24.2
  2. CVE-2026-10832Org.wildfly.security/wildfly-elytron-asn1: unbounded memory allocation in wildfly elytron asn.1 derdecoder via crafted der payload5.9
  3. CVE-2026-89058Resteasy-core: resteasy: corsfilter reflects arbitrary origin with credentials under wildcard config7.4
  4. CVE-2026-89059Resteasy-core: resteasy: iioimageprovider unbounded image decode (decompression-bomb dos)7.5
  5. CVE-2026-81829Smallrye-jwt: quarkus-smallrye-jwt: smallrye-jwt: unauthenticated same-origin ssrf via unsanitized jwt kid header in awsalbkeyresolver5.3
  6. CVE-2026-17526Keycloak-services: keycloak-services: privilege escalation via impersonation role allows takeover of realm administrator accounts7.2
  7. CVE-2026-18212Keycloak-services: keycloak-services: saml redirect deflate helpers leak native zlib state7.5
  8. CVE-2026-17615Resteasy-core: resteasy sourceprovider remote unauthenticated file read7.5
  9. CVE-2026-12894Io.quarkus:quarkus-qute: quarkus-qute:server-side template injection (ssti) vulnerability in reflectionvalueresolver of the quarkus qute template engine8.8
  10. CVE-2026-81624Undertow-core: undertow: websocketcontainer defaults for buffers and timeouts are infinite7.5
  11. CVE-2026-5680Undertow-core: undertow: denial of service via websocket permessage-deflate processing7.5
  12. CVE-2026-19611Wildfly-elytron: org.wildfly.security/wildfly-elytron-password-impl: wildfly-elytron: password keyspace reduction via nfkc fullwidth folding7.4
  13. CVE-2026-76166Modcluster-core: mod_cluster advertise listener: unauthenticated dos via crafted multicast datagram4.3
  14. CVE-2026-15571Keycloak-services: keycloak-services: predictable account-linking hash enables account takeover via malicious oidc client7.3
  15. CVE-2026-18963Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass9.1

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store