REDHAT-BUG-2524868: High severity Undertow vulnerability

Published Aug 27, 2026
·
Updated

A vulnerability was found in Undertow where the WebSocketContainer and its boot process do not allow setting the binaryBuffer and textBuffer sizes, along with session duration and async send timeout. These parameters default to infinite. This is a follow-up to CVE-2026-5680, as the initial fix allowed setting buffer sizes for certain types but left async send and session duration as infinite and inaccessible for configuration. An attacker could exploit these infinite defaults to cause resource exhaustion or an Out of Memory (OOME) condition on the server.

Affected Software

1 affected component
Undertow

Event History

Aug 27, 2026
Data Sourced
via Red Hat·08:42 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

Who is exposed to this issue?

Undertow deployments using WebSocketContainer are exposed because the binary and text buffer sizes, session duration, and asynchronous send timeout default to infinite and cannot be configured through the affected boot process.

2

What does an attacker need to do to exploit it?

An attacker would need to interact with the server's WebSocket functionality in a way that consumes unbounded resources. The stated impact is resource exhaustion or an out-of-memory condition on the server.

3

Are the default settings affected?

Yes. The affected parameters default to infinite, including session duration and asynchronous send timeout; the description also identifies binary and text buffer sizes as defaulting to infinite.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203