CVE-2026-15561: Unauthenticated Denial of Service in Red Hat JBoss Enterprise Application Platform
A vulnerability in the undertow HTTP/1.1 chunked-transfer decoder of Red Hat JBoss Enterprise Application Platform (EAP) 7.4 ELS on RHEL 7 allows an unauthenticated attacker to cause a Denial of Service (DoS) by driving the JVM to an OutOfMemory error. The vulnerability has a CVSS score of 7.5 and is not currently being actively exploited. Affected products include various packages such as eap7-activemq-artemis, eap7-glassfish-jsf, and eap7-jackson-annotations, among others. Immediate patching is recommended to prevent potential DoS attacks.