CVE-2026-5680

high Apache
CVSS v3 Base Score
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.4%
Exploitation probability in 30 days
Top 66% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Confidentiality
None
Integrity
None
Availability
High
Published: August 27, 2026 (10 days ago)
Last Modified: September 4, 2026
Vendor: Apache
Source: MITRE

Description

A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead to excessive memory consumption due to the PerMessageDeflateFunction.largerBuffer() method using exponential doubling, resulting in a Denial of Service (DoS) for the affected application.

CWE

CWE-770

Affected Products

Red Hat Red Hat build of Apache Camel for Spring Boot 4Red Hat Red Hat build of Apache Camel - HawtIO 4Red Hat Red Hat Data Grid 8Red Hat Red Hat Enterprise Linux 10Red Hat Red Hat Enterprise Linux 8Red Hat Red Hat Enterprise Linux 9Red Hat Red Hat Fuse 7Red Hat Red Hat JBoss Enterprise Application Platform 7Red Hat Red Hat JBoss Enterprise Application Platform 8Red Hat Red Hat JBoss Enterprise Application Platform Expansion Pack

References