RHEL 7 : Red Hat JBoss Enterprise Application Platform 7.4.25 security pdate (Important) (RHSA-2026:53644)

critical Nessus Plugin ID 334631

Synopsis

The remote Red Hat host is missing one or more security updates.

Description

The remote Redhat Enterprise Linux 7 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2026:53644 advisory.

Red Hat JBoss Enterprise Application Platform 7 is a platform for Java applications based on the WildFly application runtime. This release of Red Hat JBoss Enterprise Application Platform 7.4.25 serves as a replacement for Red Hat JBoss Enterprise Application Platform 7.4.24, and includes bug fixes and enhancements. See the Red Hat JBoss Enterprise Application Platform 7.4.25 Release Notes for information about the most significant bug fixes and enhancements included in this release.

Security Fix(es):

* netty-codec-redis: Netty: Denial of Service via malicious Redis array header (CVE-2026-50011)

* netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake (CVE-2026-45416)

* netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payload with deeply nested arrays (CVE-2026-44250)

* netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payloads (CVE-2026-44890)

* netty-transport-sctp: Netty-transport-sctp: Denial of Service due to unbounded memory growth from SctpMessage fragments (CVE-2026-46340)

* netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation (CVE-2026-45674)

* netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass (CVE-2026-50010)

* netty-codec-redis: Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator (CVE-2026-48006)

* netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records (CVE-2026-47691)

* netty-codec-haproxy: Netty HAProxy PROXY protocol v2 codec: Denial of Service via memory leak from crafted PROXY protocol headers (CVE-2026-48059)

* netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak (CVE-2026-48043)

* netty-codec-haproxy: Netty-codec-haproxy: Denial of Service via malformed HAProxy message (CVE-2026-44893)

* netty-codec-http: Netty: Request smuggling via malformed Transfer-Encoding parsing (CVE-2026-42585)

* netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression (CVE-2026-42587)

* netty-codec-http: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression (CVE-2026-42587)

* netty-codec-http: Netty: HTTP request smuggling via URI manipulation and CRLF injection (CVE-2026-41417)

* netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation (CVE-2026-42578)

* netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers (CVE-2026-42581)

* netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion (CVE-2026-42584)

* netty-codec-dns: Netty: High integrity impact due to improper DNS domain name constraint enforcement (CVE-2026-42579)

* picketlink-federation: auth bypass in Picketlink SAML unsolicited-response (CVE-2026-10579)

* bcprov-jdk18on: LDAP injection vulnerability in LDAPStoreHelper.java (CVE-2026-0636)

* bcprov-jdk15on: LDAP injection vulnerability in LDAPStoreHelper.java (CVE-2026-0636)

* bcprov-jdk15: LDAP injection vulnerability in LDAPStoreHelper.java (CVE-2026-0636)

* bcprov-jdk12: LDAP injection vulnerability in LDAPStoreHelper.java (CVE-2026-0636)

* bcpg-jdk18on: unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion (CVE-2026-3505)

* bcpg-jdk15on: unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion (CVE-2026-3505)

* bcpkix-jdk18on: PKIX draft CompositeVerifier accepts empty signature sequence as valid (CVE-2026-5588)

* bcpkix-jdk15on: PKIX draft CompositeVerifier accepts empty signature sequence as valid (CVE-2026-5588)

* bcprov-jdk18on: GOSTCTR implementation unable to process more than 255 blocks correctly (CVE-2025-14813)

* bcprov-jdk15on: GOSTCTR implementation unable to process more than 255 blocks correctly (CVE-2025-14813)

* bcprov-jdk15: GOSTCTR implementation unable to process more than 255 blocks correctly (CVE-2025-14813)

* bcprov-jdk12: GOSTCTR implementation unable to process more than 255 blocks correctly (CVE-2025-14813)

* bcprov-jdk15: private key leakage via non-constant time comparisons (CVE-2026-5598)

* bcprov-jdk12: private key leakage via non-constant time comparisons (CVE-2026-5598)

* artemis-server: Apache Artemis, Apache ActiveMQ Artemis: Message injection and exfiltration due to missing authentication (CVE-2026-27446)

* undertow-core: Undertow: Authentication Bypass via AJP ssl_cert/is_ssl Forgery (CVE-2026-15554)

* wildfly-clustering-infinispan-marshalling: Jboss Deserialization RCE via Unfiltered River Unmarshaller (CVE-2026-15555)

* picketlink-federation: picketlink SAML 2.0 auth bypass via missing assertions (CVE-2026-15556)

* openjdk-orb: unauthed class loading via IIOP in EAP (CVE-2026-15560)

* undertow-core: OOM via missing limits in chunked trailer in EAP's Undertow (CVE-2026-15561)

* jboss-remoting: jboss-remoting: integer overflow in MessageReader leads to pre-authentication denial of service (CVE-2026-15562)

* wildfly-iiop-openjdk: Missing authentication on EAP's IIOP NameService leads to MITM or DoS (CVE-2026-15563)

* jsf-impl: mojarra: Unauthenticated RCE in EAP JSF applications via EL injection in ui:include (CVE-2026-46581)

* netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation (CVE-2026-44249)

* jackson-core: Denial of Service via incomplete fix in async JSON parser (CVE-2026-68494)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Tenable has extracted the preceding description block directly from the Red Hat Enterprise Linux security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://access.redhat.com/errata/RHSA-2026:53644

https://access.redhat.com/security/updates/classification/#important

https://bugzilla.redhat.com/show_bug.cgi?id=2444320

https://bugzilla.redhat.com/show_bug.cgi?id=2458634

https://bugzilla.redhat.com/show_bug.cgi?id=2458635

https://bugzilla.redhat.com/show_bug.cgi?id=2458638

https://bugzilla.redhat.com/show_bug.cgi?id=2458640

https://bugzilla.redhat.com/show_bug.cgi?id=2458641

https://bugzilla.redhat.com/show_bug.cgi?id=2467540

https://bugzilla.redhat.com/show_bug.cgi?id=2477217

https://bugzilla.redhat.com/show_bug.cgi?id=2477220

https://bugzilla.redhat.com/show_bug.cgi?id=2477224

https://bugzilla.redhat.com/show_bug.cgi?id=2477226

https://bugzilla.redhat.com/show_bug.cgi?id=2477227

https://bugzilla.redhat.com/show_bug.cgi?id=2477232

https://bugzilla.redhat.com/show_bug.cgi?id=2477930

https://bugzilla.redhat.com/show_bug.cgi?id=2480325

https://bugzilla.redhat.com/show_bug.cgi?id=2480601

https://bugzilla.redhat.com/show_bug.cgi?id=2480637

https://bugzilla.redhat.com/show_bug.cgi?id=2482963

https://bugzilla.redhat.com/show_bug.cgi?id=2482965

https://bugzilla.redhat.com/show_bug.cgi?id=2483121

https://bugzilla.redhat.com/show_bug.cgi?id=2483131

https://bugzilla.redhat.com/show_bug.cgi?id=2483133

https://bugzilla.redhat.com/show_bug.cgi?id=2483135

https://bugzilla.redhat.com/show_bug.cgi?id=2483136

https://bugzilla.redhat.com/show_bug.cgi?id=2483138

https://bugzilla.redhat.com/show_bug.cgi?id=2488053

https://bugzilla.redhat.com/show_bug.cgi?id=2488062

https://bugzilla.redhat.com/show_bug.cgi?id=2488081

https://bugzilla.redhat.com/show_bug.cgi?id=2488383

https://bugzilla.redhat.com/show_bug.cgi?id=2488388

https://bugzilla.redhat.com/show_bug.cgi?id=2488391

https://bugzilla.redhat.com/show_bug.cgi?id=2488400

https://bugzilla.redhat.com/show_bug.cgi?id=2488413

https://bugzilla.redhat.com/show_bug.cgi?id=2488429

https://bugzilla.redhat.com/show_bug.cgi?id=2488433

https://bugzilla.redhat.com/show_bug.cgi?id=2488437

https://bugzilla.redhat.com/show_bug.cgi?id=2488439

https://bugzilla.redhat.com/show_bug.cgi?id=2488442

https://bugzilla.redhat.com/show_bug.cgi?id=2511026

https://issues.redhat.com/browse/JBEAP-33515

http://www.nessus.org/u?31eae5d2

http://www.nessus.org/u?764ed44a

http://www.nessus.org/u?c7aafbf8

Plugin Details

Severity: Critical

ID: 334631

File Name: redhat-RHSA-2026-53644.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 8/11/2026

Updated: 8/11/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 94.16

Vendor

Vendor Severity: Important

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-42581

CVSS v3

Risk Factor: Critical

Base Score: 10

Temporal Score: 9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS Score Source: CVE-2026-47691

CVSS v4

Risk Factor: Critical

Base Score: 9.9

Threat Score: 9.2

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N

CVSS Score Source: CVE-2026-5598

Vulnerability Information

CPE: cpe:/o:redhat:enterprise_linux:7, p-cpe:/a:redhat:enterprise_linux:eap7-activemq-artemis-cli, p-cpe:/a:redhat:enterprise_linux:eap7-activemq-artemis-commons, p-cpe:/a:redhat:enterprise_linux:eap7-activemq-artemis-core-client, p-cpe:/a:redhat:enterprise_linux:eap7-activemq-artemis-dto, p-cpe:/a:redhat:enterprise_linux:eap7-activemq-artemis-hornetq-protocol, p-cpe:/a:redhat:enterprise_linux:eap7-activemq-artemis-hqclient-protocol, p-cpe:/a:redhat:enterprise_linux:eap7-activemq-artemis-jdbc-store, p-cpe:/a:redhat:enterprise_linux:eap7-activemq-artemis-jms-client, p-cpe:/a:redhat:enterprise_linux:eap7-activemq-artemis-jms-server, p-cpe:/a:redhat:enterprise_linux:eap7-activemq-artemis-journal, p-cpe:/a:redhat:enterprise_linux:eap7-activemq-artemis-ra, p-cpe:/a:redhat:enterprise_linux:eap7-activemq-artemis-selector, p-cpe:/a:redhat:enterprise_linux:eap7-activemq-artemis-server, p-cpe:/a:redhat:enterprise_linux:eap7-activemq-artemis-service-extensions, p-cpe:/a:redhat:enterprise_linux:eap7-activemq-artemis-tools, p-cpe:/a:redhat:enterprise_linux:eap7-activemq-artemis, p-cpe:/a:redhat:enterprise_linux:eap7-glassfish-jsf, p-cpe:/a:redhat:enterprise_linux:eap7-ironjacamar-common-api, p-cpe:/a:redhat:enterprise_linux:eap7-ironjacamar-common-impl, p-cpe:/a:redhat:enterprise_linux:eap7-ironjacamar-common-spi, p-cpe:/a:redhat:enterprise_linux:eap7-ironjacamar-core-api, p-cpe:/a:redhat:enterprise_linux:eap7-ironjacamar-core-impl, p-cpe:/a:redhat:enterprise_linux:eap7-ironjacamar-deployers-common, p-cpe:/a:redhat:enterprise_linux:eap7-ironjacamar-jdbc, p-cpe:/a:redhat:enterprise_linux:eap7-ironjacamar-validator, p-cpe:/a:redhat:enterprise_linux:eap7-ironjacamar, p-cpe:/a:redhat:enterprise_linux:eap7-jackson-annotations, p-cpe:/a:redhat:enterprise_linux:eap7-jackson-core, p-cpe:/a:redhat:enterprise_linux:eap7-jackson-databind, p-cpe:/a:redhat:enterprise_linux:eap7-jackson-datatype-jdk8, p-cpe:/a:redhat:enterprise_linux:eap7-jackson-datatype-jsr310, p-cpe:/a:redhat:enterprise_linux:eap7-jackson-jaxrs-base, p-cpe:/a:redhat:enterprise_linux:eap7-jackson-jaxrs-json-provider, p-cpe:/a:redhat:enterprise_linux:eap7-jackson-jaxrs-providers, p-cpe:/a:redhat:enterprise_linux:eap7-jackson-module-jaxb-annotations, p-cpe:/a:redhat:enterprise_linux:eap7-jackson-modules-base, p-cpe:/a:redhat:enterprise_linux:eap7-jackson-modules-java8, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-remoting, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-server-migration-cli, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-server-migration-core, p-cpe:/a:redhat:enterprise_linux:eap7-jboss-server-migration, p-cpe:/a:redhat:enterprise_linux:eap7-netty-all, p-cpe:/a:redhat:enterprise_linux:eap7-netty-buffer, p-cpe:/a:redhat:enterprise_linux:eap7-netty-codec-dns, p-cpe:/a:redhat:enterprise_linux:eap7-netty-codec-haproxy, p-cpe:/a:redhat:enterprise_linux:eap7-netty-codec-http2, p-cpe:/a:redhat:enterprise_linux:eap7-netty-codec-http, p-cpe:/a:redhat:enterprise_linux:eap7-netty-codec-memcache, p-cpe:/a:redhat:enterprise_linux:eap7-netty-codec-mqtt, p-cpe:/a:redhat:enterprise_linux:eap7-netty-codec-redis, p-cpe:/a:redhat:enterprise_linux:eap7-netty-codec-smtp, p-cpe:/a:redhat:enterprise_linux:eap7-netty-codec-socks, p-cpe:/a:redhat:enterprise_linux:eap7-netty-codec-stomp, p-cpe:/a:redhat:enterprise_linux:eap7-netty-codec-xml, p-cpe:/a:redhat:enterprise_linux:eap7-netty-codec, p-cpe:/a:redhat:enterprise_linux:eap7-netty-common, p-cpe:/a:redhat:enterprise_linux:eap7-netty-handler-proxy, p-cpe:/a:redhat:enterprise_linux:eap7-netty-handler, p-cpe:/a:redhat:enterprise_linux:eap7-netty-resolver-dns-classes-macos, p-cpe:/a:redhat:enterprise_linux:eap7-netty-resolver-dns, p-cpe:/a:redhat:enterprise_linux:eap7-netty-resolver, p-cpe:/a:redhat:enterprise_linux:eap7-netty-transport-classes-epoll, p-cpe:/a:redhat:enterprise_linux:eap7-netty-transport-classes-kqueue, p-cpe:/a:redhat:enterprise_linux:eap7-netty-transport-native-epoll, p-cpe:/a:redhat:enterprise_linux:eap7-netty-transport-native-unix-common, p-cpe:/a:redhat:enterprise_linux:eap7-netty-transport-sctp, p-cpe:/a:redhat:enterprise_linux:eap7-netty-transport, p-cpe:/a:redhat:enterprise_linux:eap7-netty, p-cpe:/a:redhat:enterprise_linux:eap7-picketlink-api, p-cpe:/a:redhat:enterprise_linux:eap7-picketlink-bindings, p-cpe:/a:redhat:enterprise_linux:eap7-picketlink-common, p-cpe:/a:redhat:enterprise_linux:eap7-picketlink-config, p-cpe:/a:redhat:enterprise_linux:eap7-picketlink-federation, p-cpe:/a:redhat:enterprise_linux:eap7-picketlink-idm-api, p-cpe:/a:redhat:enterprise_linux:eap7-picketlink-idm-impl, p-cpe:/a:redhat:enterprise_linux:eap7-picketlink-idm-simple-schema, p-cpe:/a:redhat:enterprise_linux:eap7-picketlink-impl, p-cpe:/a:redhat:enterprise_linux:eap7-picketlink-wildfly8, p-cpe:/a:redhat:enterprise_linux:eap7-undertow, p-cpe:/a:redhat:enterprise_linux:eap7-wildfly-java-jdk11, p-cpe:/a:redhat:enterprise_linux:eap7-wildfly-java-jdk8, p-cpe:/a:redhat:enterprise_linux:eap7-wildfly-javadocs, p-cpe:/a:redhat:enterprise_linux:eap7-wildfly-modules, p-cpe:/a:redhat:enterprise_linux:eap7-wildfly

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 8/11/2026

Vulnerability Publication Date: 3/4/2026

Reference Information

CVE: CVE-2025-14813, CVE-2026-0636, CVE-2026-10579, CVE-2026-15554, CVE-2026-15555, CVE-2026-15556, CVE-2026-15560, CVE-2026-15561, CVE-2026-15562, CVE-2026-15563, CVE-2026-27446, CVE-2026-3505, CVE-2026-41417, CVE-2026-42578, CVE-2026-42579, CVE-2026-42581, CVE-2026-42584, CVE-2026-42585, CVE-2026-42587, CVE-2026-44249, CVE-2026-44250, CVE-2026-44890, CVE-2026-44893, CVE-2026-45416, CVE-2026-45674, CVE-2026-46340, CVE-2026-46581, CVE-2026-47691, CVE-2026-48006, CVE-2026-48043, CVE-2026-48059, CVE-2026-50010, CVE-2026-50011, CVE-2026-5588, CVE-2026-5598, CVE-2026-68494

CWE: 1286, 1287, 190, 295, 306, 327, 346, 347, 385, 444, 502, 770, 772, 805, 829, 90, 93, 94

RHSA: 2026:53644