RHSA-2026:3951: Important: JBoss EAP XP 5.0 Update 4.0 release. See references for release notes.
Important: JBoss EAP XP 5.0 Update 4.0 release. See references for release notes.
Other sources
JBoss EAP XP 5.0 Update 4.0 GA release. See references for release notes.Security Fix(es): vertx-core: static handler component cache can be manipulated to deny the access to static files [eapxp-5] (CVE-2026-1002) netty-codec: Netty's BrotliDecoder is vulnerable to DoS via zip bomb style attack [eapxp-5] (CVE-2025-58057) lz4-java: lz4-java: Information Disclosure via Insufficient Output Buffer Clearing [eapxp-5] (CVE-2025-66566) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:3951?
The severity of RHSA-2026:3951 is classified as Important.
What software is affected by RHSA-2026:3951?
RHSA-2026:3951 affects the Red Hat JBoss Enterprise Application Platform.
How do I fix RHSA-2026:3951?
To address RHSA-2026:3951, you should update to JBoss EAP XP 5.0 Update 4.0.
What security issues are addressed in RHSA-2026:3951?
RHSA-2026:3951 addresses security flaws in the vertx-core static handler component cache.
Is there a release note for RHSA-2026:3951?
Yes, RHSA-2026:3951 includes release notes that detail the changes and updates.