AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-15561

HIGH · CVSS 7.5 EPSS 0.35%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A vulnerability exists in EAP's undertow HTTP/1.1 chunked-transfer decoder, which lacks proper limits on size and count. This flaw can be exploited by an attacker to trigger an OutOfMemory error in the JVM through an unauthenticated connection, resulting in a Denial of Service that halts all deployments on the listener. Organizations using affected EAP products should prioritize addressing this issue to prevent potential service disruptions.

CVE
CVE-2026-15561
Severity
HIGH
CVSS
7.5
EPSS
0.35%

Original NVD Description

A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments on the listener, and achieving Denial of Service.