All 4 CVE vulnerabilities found in Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 10, with AI-generated Chinese analysis, references, and POCs.
Vendor: Red Hat
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-85511 | Wildfly-elytron-realm-token: parameter injection in eap's elytron oauth2 CWE-290 | 4.2 | Medium | 2026-09-18 |
| CVE-2026-10832 | Org.wildfly.security/wildfly-elytron-asn1: unbounded memory allocation in wildfly elytron asn.1 derdecoder via crafted der payload CWE-770 | 5.9 | Medium | 2026-09-18 |
| CVE-2026-5680 | Undertow-core: undertow: denial of service via websocket permessage-deflate processing CWE-770 | 7.5 | High | 2026-08-27 |
| CVE-2026-14180 | Undertow-core: undertow:http request smuggling via oversized chunk-size bit overlap CWE-444 | 5.3 | Medium | 2026-08-11 |
All 4 known CVE vulnerabilities affecting Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 10 with full Chinese analysis, references, and POCs where available.