Junglewise Threat Intelligence

CVE-2026-15561: Red Hat Undertow HTTP/1.1 chunked-transfer decoder denial of service

CVE-2026-15561 · Severity: high · CVSS 7.5 · Published 2026-08-11

Technologies: Red Hat Enterprise Application Platform. Vendors: Red Hat.

Executive brief

Red Hat's Undertow is an HTTP server component used in enterprise Java application servers. A flaw in its HTTP/1.1 chunked-transfer decoder allows an unauthenticated remote attacker to exhaust server memory by sending specially crafted requests, causing the JVM to run out of memory and crashing all deployments on an affected listener.

Technical details

The vulnerability exists in Undertow's HTTP/1.1 chunked-transfer decoder, which lacks proper limits on the size and count of chunks. An unauthenticated attacker can exploit this via the network by sending HTTP requests with maliciously crafted chunked transfer encoding. The attack causes unbounded memory allocation in the JVM, triggering an OutOfMemory error that halts all deployments listening on the affected port. No authentication is required to exploit this vulnerability. Patches are expected to be available from Red Hat for affected Enterprise Application Platform versions.

Affected products

  • Red Hat Enterprise Application Platform <UNKNOWN>

Timeline

  • 2026-08-11: disclosed

References

Related threats