Red Hat Jboss Enterprise Application Platform Expansion Pack
151 CVEs tracked. 1 of them are in CISA KEV.
This hub aggregates every CVE we track for Red Hat Jboss Enterprise Application Platform Expansion Pack, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
Red Hat Jboss Enterprise Application Platform Expansion Pack CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 3 |
| 2024-11 | 2 |
| 2024-12 | 2 |
| 2025-01 | 6 |
| 2025-02 | 1 |
| 2025-03 | 2 |
| 2025-04 | 1 |
| 2025-05 | 0 |
| 2025-06 | 1 |
| 2025-07 | 1 |
| 2025-08 | 0 |
| 2025-09 | 2 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 1 |
| 2026-01 | 8 |
| 2026-02 | 3 |
| 2026-03 | 9 |
| 2026-04 | 1 |
| 2026-05 | 0 |
| 2026-06 | 5 |
| 2026-07 | 28 |
| 2026-08 | 34 |
| 2026-09 | 7 |
Severity
How the 151 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical4
- High53
- Medium83
- Low11
Latest CVEs
The 15 most recently published vulnerabilities affecting Red Hat Jboss Enterprise Application Platform Expansion Pack.
- CVE-2026-85511Wildfly-elytron-realm-token: parameter injection in eap's elytron oauth24.2
- CVE-2026-10832Org.wildfly.security/wildfly-elytron-asn1: unbounded memory allocation in wildfly elytron asn.1 derdecoder via crafted der payload5.9
- CVE-2026-89058Resteasy-core: resteasy: corsfilter reflects arbitrary origin with credentials under wildcard config7.4
- CVE-2026-89059Resteasy-core: resteasy: iioimageprovider unbounded image decode (decompression-bomb dos)7.5
- CVE-2026-81829Smallrye-jwt: quarkus-smallrye-jwt: smallrye-jwt: unauthenticated same-origin ssrf via unsanitized jwt kid header in awsalbkeyresolver5.3
- CVE-2026-17526Keycloak-services: keycloak-services: privilege escalation via impersonation role allows takeover of realm administrator accounts7.2
- CVE-2026-18212Keycloak-services: keycloak-services: saml redirect deflate helpers leak native zlib state7.5
- CVE-2026-17615Resteasy-core: resteasy sourceprovider remote unauthenticated file read7.5
- CVE-2026-12894Io.quarkus:quarkus-qute: quarkus-qute:server-side template injection (ssti) vulnerability in reflectionvalueresolver of the quarkus qute template engine8.8
- CVE-2026-81624Undertow-core: undertow: websocketcontainer defaults for buffers and timeouts are infinite7.5
- CVE-2026-5680Undertow-core: undertow: denial of service via websocket permessage-deflate processing7.5
- CVE-2026-19611Wildfly-elytron: org.wildfly.security/wildfly-elytron-password-impl: wildfly-elytron: password keyspace reduction via nfkc fullwidth folding7.4
- CVE-2026-76166Modcluster-core: mod_cluster advertise listener: unauthenticated dos via crafted multicast datagram4.3
- CVE-2026-15571Keycloak-services: keycloak-services: predictable account-linking hash enables account takeover via malicious oidc client7.3
- CVE-2026-18963Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass9.1
Product grouping is registry-driven, with AI assist and human review. How it works