CVE-2026-81624: Undertow-core: undertow: websocketcontainer defaults for buffers and timeouts are infinite

Published Aug 27, 2026
·
Updated

A vulnerability was found in Undertow where the WebSocketContainer and its boot process do not allow setting the binaryBuffer and textBuffer sizes, along with session duration and async send timeout. These parameters default to infinite. This is a follow-up to CVE-2026-5680, as the initial fix allowed setting buffer sizes for certain types but left async send and session duration as infinite and inaccessible for configuration. An attacker could exploit these infinite defaults to cause resource exhaustion or an Out of Memory (OOME) condition on the server.

Other sources

Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how Undertow handles WebSocket connections. Specifically, certain configuration limits like message buffer sizes and session timeouts cannot be adjusted and default to being unlimited. This allows a remote attacker to send large amounts of data or maintain connections indefinitely, potentially crashing the server by exhausting its memory or other resources.

MITRE

Affected Software

1 affected component
Eclipse Undertow=

Event History

Aug 27, 2026
Data Sourced
via Red Hat·08:42 AM
DescriptionSeverityAffected Software
Aug 31, 2026
CVE Published
via MITRE·08:47 AM
Data Sourced
via MITRE·08:47 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Servers using Undertow with WebSocket connections are exposed, including Undertow deployments in JBoss EAP and WildFly. The vulnerable behavior concerns WebSocketContainer defaults that leave message buffers and connection-related timeouts unlimited.

2

What does an attacker need to exploit it?

A remote attacker can exploit the issue by sending large volumes of WebSocket data or keeping WebSocket connections open indefinitely. The supplied severity vector indicates no privileges or user interaction are required.

3

Are default settings affected?

Yes. The affected binary and text buffer sizes, session duration, and asynchronous send timeout default to infinite values and cannot be configured through the affected boot process.

4

What is the likely impact of successful exploitation?

An attacker may exhaust server memory or other resources, potentially causing an out-of-memory condition and crashing the server. The reported impact is availability loss rather than confidentiality or integrity loss.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203