Executive brief
Red Hat Enterprise Application Platform (EAP) is a Java-based application server used to run enterprise business applications. A flaw in its jboss-remoting component allows remote attackers to cause out-of-memory errors that degrade server performance and availability across all running requests, resulting in denial of service without requiring authentication.
Technical details
The vulnerability exists in EAP's jboss-remoting library and can be exploited via the Upgrade handshake mechanism on network ports 8080, 9990, or 4447. A remote unauthenticated attacker who can reach these ports can trigger out-of-memory (OOM) errors that impact the entire server, degrading or blocking legitimate requests. The attack requires network connectivity to the affected ports and completion of the jboss-remoting handshake. The flaw allows an attacker to conduct a denial-of-service attack without prior authentication or special privileges. Patches or updates are expected to be available from Red Hat.
Affected products
- Red Hat Enterprise Application Platform <UNKNOWN>
Timeline
- 2026-08-11: disclosed