A security update is now available for Red Hat JBoss Enterprise Application Platform 8.1.7.1, XP 6.0.5.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.Security Fix(es): memory exhaustion in io.netty:netty-codec-haproxy (CVE-2026-48059) DNS cache poisoning in io.netty:netty-resolver-dns (CVE-2026-47691) DDoS in io.netty:netty-codec-http2 (CVE-2026-50560) memory exhaustion in io.netty:netty-codec-redis (CVE-2026-50011) memory exhaustion in io.netty:netty-codec-redis (CVE-2026-44250) memory exhaustion in io.netty:netty-codec-redis (CVE-2026-44890) IPv6 subnet filter bypass in io.netty:netty-handler (CVE-2026-44249) request smuggling in io.netty:netty-codec-http (CVE-2026-50020) memory leak in io.netty:netty-codec-haproxy (CVE-2026-44893) TLS hostname verification accidentally disabled in io.netty:netty-handler (CVE-2026-50010) DNS cache poisoning in io.netty:netty-resolver-dns (CVE-2026-45673) excessive memory usage from SNIHandler in io.netty:netty-handler (CVE-2026-45416) file descriptor leak in io.netty:netty-transport-native-epoll and io.netty:netty-transport-native-kqueue (CVE-2026-45536) DNS cache poisoning in io.netty:netty-resolver-dns (CVE-2026-45674) memory exhaustion in io.netty:netty-transport-sctp (CVE-2026-46340) denial of service in io.netty:netty-codec-http2 (CVE-2026-47244) memory exhaustion in io.netty:netty-codec-redis (CVE-2026-48006) memory exhaustion in io.netty:netty-codec-http2 (CVE-2026-48043) netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression (CVE-2026-42587) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Important: Red Hat JBoss Enterprise Application Platform 8.1.7 security update
Moderate: Red Hat JBoss Enterprise Application Platform 8.1.7 XP 6.0.5.GA release
Moderate: Red Hat JBoss Enterprise Application Platform 8.1.7 security update
Moderate: Red Hat JBoss Enterprise Application Platform 8.1.7 security update
Moderate: Red Hat JBoss Enterprise Application Platform 8.1.7 security update
Important: Red Hat JBoss Enterprise Application Platform 8.1.6 security update
Important: Red Hat JBoss Enterprise Application Platform 8.1.6 security update
Important: Red Hat JBoss Enterprise Application Platform 7.4.24 security update
Moderate: Red Hat JBoss Enterprise Application Platform 8.1.5 XP 6.0.3.GA release
Important: Red Hat JBoss Enterprise Application Platform 7.4.24 security update
Important: Red Hat JBoss Enterprise Application Platform 8.1.5 update
Important: Red Hat JBoss Enterprise Application Platform 8.0.12 security update
Important: Red Hat JBoss Enterprise Application Platform 8.0.12 security update
Important: JBoss EAP XP 5.0 Update 4.0 release. See references for release notes.
Important: Red Hat JBoss Enterprise Application Platform 8.1.4 XP 6.0.2.GA release
Important: Red Hat JBoss Enterprise Application Platform 8.1.4 security update
Important: Red Hat JBoss Enterprise Application Platform 8.1.3 security update
Important: Red Hat JBoss Enterprise Application Platform 8.1.3 security update
Important: Red Hat JBoss Enterprise Application Platform 8.1.3 security update
Moderate: Red Hat JBoss Enterprise Application Platform 8.0.11 security update
Moderate: Red Hat JBoss Enterprise Application Platform 8.0.11 security update
Moderate: Red Hat JBoss Enterprise Application Platform 8.0.11 security update
Moderate: Red Hat JBoss Enterprise Application Platform 8.1.2 Security update
Moderate: Red Hat JBoss Enterprise Application Platform 8.1.2 security update
Important: Red Hat JBoss Enterprise Application Platform 7.4.23 Security update
Important: Red Hat JBoss Enterprise Application Platform 8.0.8 Security update
Important: Red Hat JBoss Enterprise Application Platform 8.0.8 Security update
Important: Red Hat JBoss Enterprise Application Platform 8.0.8 Security update
Important: Red Hat JBoss Enterprise Application Platform 7.1.10 on RHEL 7 security update