HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-15561 — A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing li...

·Source: NIST NVD

Updated:

Executive Summary

A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments on the listener, and achieving Denial of Service.

Analysis

A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments on the listener, and achieving Denial of Service. CVSS Score: 7.5. Published: 2026-08-11T09:17:12.963.

Indicators of Compromise (1)

CVE (1)
CVE-2026-15561
Source Attribution

Originally published by NIST NVD on Aug 11, 2026. Verified by: NIST.

Related Threats