RHEL 8 : Red Hat JBoss Enterprise Application Platform 8.1.8 (RHSA-2026:70228)

high Nessus Plugin ID 348800

Synopsis

The remote Red Hat host is missing one or more security updates for Red Hat JBoss Enterprise Application Platform 8.1.8.

Description

The remote Redhat Enterprise Linux 8 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2026:70228 advisory.

Red Hat JBoss Enterprise Application Platform 8 is a platform for Java applications based on the WildFly application runtime. This release of Red Hat JBoss Enterprise Application Platform 8.1.8 serves as a replacement for Red Hat JBoss Enterprise Application Platform 8.1.7, and includes bug fixes and enhancements. See the Red Hat JBoss Enterprise Application Platform 8.1.8 Release Notes for information about the most significant bug fixes and enhancements included in this release.

Security Fix(es):

* jackson-core: jackson-core: Denial of Service via incomplete fix in async JSON parser [eap-8.1.z] (CVE-2026-68494)

* netty-codec-http2: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec [eap-8.1.z] (CVE-2026-56745)

* netty-handler: Netty: TLS hostname verification bypass via OpenSSL client path misconfiguration [eap-8.1.z] (CVE-2026-62243)

* bcpg-jdk18on: Bouncy Castle for Java: Denial of Service due to unbounded OpenPGP user-attribute subpacket length [eap-8.1.z] (CVE-2026-59649)

* jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified [eap-8.1.z] (CVE-2026-54515)

* jackson-databind: Jackson-databind: Privilege escalation via improper handling of @JsonUnwrapped properties [eap-8.1.z] (CVE-2026-59889)

* netty-codec-dns: Netty: Denial of Service via Memory Leak in DNS Record Decoder with Malformed Domain Names [eap-8.1.z] (CVE-2026-73508)

* jboss-eap.1-runtime-maven-repository.zip: jackson-core: Denial of Service via incomplete fix in async JSON parser [eap-8.1.z] (CVE-2026-68494)

* jboss-eap-runtime-maven-repository.zip: jackson-core: Denial of Service via incomplete fix in async JSON parser [eap-8.1.z] (CVE-2026-68494)

* bcprov-jdk18on: unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion [eap-8.1.z] (CVE-2026-3505)

* brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays [eap-8.1.z] (CVE-2026-69152)

* netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb) [eap-8.1.z] (CVE-2026-59899)

* netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header [eap-8.1.z] (CVE-2026-56746)

* netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec [eap-8.1.z] (CVE-2026-56745)

* netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing [eap-8.1.z] (CVE-2026-55831)

* netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification [eap-8.1.z] (CVE-2026-55833)

* jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution [eap-8.1.z] (CVE-2026-54513)

* jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass [eap-8.1.z] (CVE-2026-54512)

* undertow-core: Undertow:HTTP request smuggling via oversized chunk-size bit overlap [eap-8.1.z] (CVE-2026-14180)

* artemis-server: artemis-server: Pre-auth topology disclosure via CORE SUBSCRIBE_TOPOLOGY_V2 on channel0 [eap-8.1.z] (CVE-2026-49363)

* undertow-websockets-jsr: Undertow: Pre-Auth DoS on websocket endpoint with @ServerEndpoint class with any @OnMessage method [eap-8.1.z] (CVE-2026-15565)

* wildfly-iiop-openjdk: Wildfly: Pre-auth denial of service on the IIOP listener [eap-8.1.z] (CVE-2026-15567)

* cxf-rt-transports-jms: Apache CXF: Arbitrary code execution via untrusted JMS configuration [eap-8.1.z] (CVE-2026-50632)

* cxf-core: Apache CXF: Information disclosure via out-of-band external entity resolution due to missing JAXP hardening [eap-8.1.z] (CVE-2026-49875)

* wildfly-elytron-asn1: Unbounded Memory Allocation in WildFly Elytron ASN.1 DERDecoder via Crafted DER Payload [eap-8.1.z] (CVE-2026-10832)

* cxf-rt-transports-jms: Apache CXF: Remote Code Execution via untrusted JMS configuration [eap-8.1.z] (CVE-2026-44417)

* wildfly-elytron-realm-token: parameter injection in EAP's elytron oauth2 [eap-8.1.z] (CVE-2026-85511)

* jakarta.faces: mojarra: Unauthenticated RCE in EAP JSF applications via EL injection in ui:include [eap-8.1.z] (CVE-2026-46581)

* wildfly-iiop-openjdk: Missing authentication on EAP's IIOP NameService leads to MITM or DoS [eap-8.1.z] (CVE-2026-15563)

* jboss-remoting: jboss-remoting: integer overflow in MessageReader leads to pre-authentication denial of service [eap-8.1.z] (CVE-2026-15562)

* undertow-core: OOM via missing limits in chunked trailer in EAP's Undertow [eap-8.1.z] (CVE-2026-15561)

* openjdk-orb: unauthed class loading via IIOP in EAP [eap-8.1.z] (CVE-2026-15560)

* artemis-server: Apache Artemis session hijack via missing authentication [eap-8.1.z] (CVE-2026-57967)

* wildfly-clustering-infinispan-marshalling: Jboss Deserialization RCE via Unfiltered River Unmarshaller [eap-8.1.z] (CVE-2026-15555)

* undertow-core: Undertow: Authentication Bypass via AJP ssl_cert/is_ssl Forgery [eap-8.1.z] (CVE-2026-15554)

* jgroups: artemis cluster password leak via jgroups spoof [eap-8.1.z] (CVE-2026-49364)

* artemis-server: artemis core protocol permits unauthed queue creation [eap-8.1.z] (CVE-2026-49362)

* artemis-server: artemis messaging handlers in Red Hat EAP permit deserialization by default [eap-8.1.z] (CVE-2026-86404)

* undertow-core: Undertow: Denial of Service via WebSocket permessage-deflate processing [eap-8.1.z] (CVE-2026-5680)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Tenable has extracted the preceding description block directly from the Red Hat Enterprise Linux security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the RHEL Red Hat JBoss Enterprise Application Platform 8.1.8 package based on the guidance in RHSA-2026:70228.

See Also

https://access.redhat.com/articles/7137769

https://access.redhat.com/errata/RHSA-2026:70228

https://access.redhat.com/security/updates/classification/#important

https://bugzilla.redhat.com/show_bug.cgi?id=2455350

https://bugzilla.redhat.com/show_bug.cgi?id=2458638

https://bugzilla.redhat.com/show_bug.cgi?id=2477930

https://bugzilla.redhat.com/show_bug.cgi?id=2477945

https://bugzilla.redhat.com/show_bug.cgi?id=2478013

https://bugzilla.redhat.com/show_bug.cgi?id=2480601

https://bugzilla.redhat.com/show_bug.cgi?id=2480637

https://bugzilla.redhat.com/show_bug.cgi?id=2480638

https://bugzilla.redhat.com/show_bug.cgi?id=2480729

https://bugzilla.redhat.com/show_bug.cgi?id=2483131

https://bugzilla.redhat.com/show_bug.cgi?id=2483133

https://bugzilla.redhat.com/show_bug.cgi?id=2483135

https://bugzilla.redhat.com/show_bug.cgi?id=2483136

https://bugzilla.redhat.com/show_bug.cgi?id=2483138

https://bugzilla.redhat.com/show_bug.cgi?id=2483140

https://bugzilla.redhat.com/show_bug.cgi?id=2484703

https://bugzilla.redhat.com/show_bug.cgi?id=2488304

https://bugzilla.redhat.com/show_bug.cgi?id=2488309

https://bugzilla.redhat.com/show_bug.cgi?id=2490628

https://bugzilla.redhat.com/show_bug.cgi?id=2491620

https://bugzilla.redhat.com/show_bug.cgi?id=2492010

https://bugzilla.redhat.com/show_bug.cgi?id=2492015

https://bugzilla.redhat.com/show_bug.cgi?id=2492016

https://bugzilla.redhat.com/show_bug.cgi?id=2492627

https://bugzilla.redhat.com/show_bug.cgi?id=2494771

https://bugzilla.redhat.com/show_bug.cgi?id=2500653

https://bugzilla.redhat.com/show_bug.cgi?id=2503101

https://bugzilla.redhat.com/show_bug.cgi?id=2503103

https://bugzilla.redhat.com/show_bug.cgi?id=2505422

https://bugzilla.redhat.com/show_bug.cgi?id=2505911

https://bugzilla.redhat.com/show_bug.cgi?id=2507482

https://bugzilla.redhat.com/show_bug.cgi?id=2510195

https://bugzilla.redhat.com/show_bug.cgi?id=2510722

https://bugzilla.redhat.com/show_bug.cgi?id=2511026

https://bugzilla.redhat.com/show_bug.cgi?id=2515377

https://bugzilla.redhat.com/show_bug.cgi?id=2521309

https://issues.redhat.com/browse/JBEAP-32314

https://issues.redhat.com/browse/JBEAP-32869

https://issues.redhat.com/browse/JBEAP-33162

https://issues.redhat.com/browse/JBEAP-33185

https://issues.redhat.com/browse/JBEAP-33236

https://issues.redhat.com/browse/JBEAP-33237

https://issues.redhat.com/browse/JBEAP-33288

https://issues.redhat.com/browse/JBEAP-33363

https://issues.redhat.com/browse/JBEAP-33405

https://issues.redhat.com/browse/JBEAP-33409

https://issues.redhat.com/browse/JBEAP-33413

https://issues.redhat.com/browse/JBEAP-33449

https://issues.redhat.com/browse/JBEAP-33459

https://issues.redhat.com/browse/JBEAP-33501

https://issues.redhat.com/browse/JBEAP-33579

https://issues.redhat.com/browse/JBEAP-33616

https://issues.redhat.com/browse/JBEAP-33640

https://issues.redhat.com/browse/JBEAP-33683

https://issues.redhat.com/browse/JBEAP-33848

https://issues.redhat.com/browse/JBEAP-33871

https://issues.redhat.com/browse/JBEAP-33904

https://issues.redhat.com/browse/JBEAP-33925

https://issues.redhat.com/browse/JBEAP-33967

https://issues.redhat.com/browse/JBEAP-33968

https://issues.redhat.com/browse/JBEAP-33973

https://issues.redhat.com/browse/JBEAP-34018

https://issues.redhat.com/browse/JBEAP-34095

https://issues.redhat.com/browse/JBEAP-34096

https://issues.redhat.com/browse/JBEAP-34111

https://issues.redhat.com/browse/JBEAP-34161

https://issues.redhat.com/browse/JBEAP-34222

https://issues.redhat.com/browse/JBEAP-34521

http://www.nessus.org/u?29b6d808

http://www.nessus.org/u?4f7c1c91

http://www.nessus.org/u?944f16bf

Plugin Details

Severity: High

ID: 348800

File Name: redhat-RHSA-2026-70228.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 9/22/2026

Updated: 9/22/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 96.81

Vendor

Vendor Severity: Important

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-49875

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.7

Threat Score: 7.7

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2026-68494

Vulnerability Information

CPE: cpe:/o:redhat:enterprise_linux:8, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-cli, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-commons, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-core-client, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-dto, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-hornetq-protocol, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-hqclient-protocol, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-jakarta-client, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-jakarta-ra, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-jakarta-server, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-jakarta-service-extensions, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-jdbc-store, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-journal, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-selector, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis-server, p-cpe:/a:redhat:enterprise_linux:eap8-activemq-artemis, p-cpe:/a:redhat:enterprise_linux:eap8-apache-cxf-rt, p-cpe:/a:redhat:enterprise_linux:eap8-apache-cxf-services, p-cpe:/a:redhat:enterprise_linux:eap8-apache-cxf-tools, p-cpe:/a:redhat:enterprise_linux:eap8-apache-cxf, p-cpe:/a:redhat:enterprise_linux:eap8-artemis-wildfly-integration, p-cpe:/a:redhat:enterprise_linux:eap8-bouncycastle-jmail, p-cpe:/a:redhat:enterprise_linux:eap8-bouncycastle-pg, p-cpe:/a:redhat:enterprise_linux:eap8-bouncycastle-pkix, p-cpe:/a:redhat:enterprise_linux:eap8-bouncycastle-prov, p-cpe:/a:redhat:enterprise_linux:eap8-bouncycastle-util, p-cpe:/a:redhat:enterprise_linux:eap8-bouncycastle, p-cpe:/a:redhat:enterprise_linux:eap8-codemodel, p-cpe:/a:redhat:enterprise_linux:eap8-cryptacular, p-cpe:/a:redhat:enterprise_linux:eap8-eap-product-conf-parent, p-cpe:/a:redhat:enterprise_linux:eap8-eap-product-conf-wildfly-ee-feature-pack, p-cpe:/a:redhat:enterprise_linux:eap8-hibernate-core, p-cpe:/a:redhat:enterprise_linux:eap8-hibernate-envers, p-cpe:/a:redhat:enterprise_linux:eap8-hibernate, p-cpe:/a:redhat:enterprise_linux:eap8-httpcomponents-asyncclient, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar-common-api, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar-common-impl, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar-common-spi, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar-core-api, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar-core-impl, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar-deployers-common, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar-jdbc, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar-validator, p-cpe:/a:redhat:enterprise_linux:eap8-ironjacamar, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-annotations, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-core, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-databind, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-dataformat-yaml, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-dataformats-text, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-datatype-jdk8, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-datatype-jsr310, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-jaxrs-base, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-jaxrs-json-provider, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-jaxrs-providers, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-module-jakarta-xmlbind-annotations, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-modules-base, p-cpe:/a:redhat:enterprise_linux:eap8-jackson-modules-java8, p-cpe:/a:redhat:enterprise_linux:eap8-jakarta-xml-bind-api, p-cpe:/a:redhat:enterprise_linux:eap8-jaxb-core, p-cpe:/a:redhat:enterprise_linux:eap8-jaxb-jxc, p-cpe:/a:redhat:enterprise_linux:eap8-jaxb-runtime, p-cpe:/a:redhat:enterprise_linux:eap8-jaxb-xjc, p-cpe:/a:redhat:enterprise_linux:eap8-jaxb, p-cpe:/a:redhat:enterprise_linux:eap8-jaxbintros, p-cpe:/a:redhat:enterprise_linux:eap8-jboss-logging, p-cpe:/a:redhat:enterprise_linux:eap8-jboss-remoting, p-cpe:/a:redhat:enterprise_linux:eap8-jbossws-api, p-cpe:/a:redhat:enterprise_linux:eap8-jbossws-common-tools, p-cpe:/a:redhat:enterprise_linux:eap8-jbossws-cxf, p-cpe:/a:redhat:enterprise_linux:eap8-jbossws-jaxws-undertow-httpspi, p-cpe:/a:redhat:enterprise_linux:eap8-jbossws-spi, p-cpe:/a:redhat:enterprise_linux:eap8-jsf-impl, p-cpe:/a:redhat:enterprise_linux:eap8-log4j, p-cpe:/a:redhat:enterprise_linux:eap8-neethi, p-cpe:/a:redhat:enterprise_linux:eap8-netty-buffer, p-cpe:/a:redhat:enterprise_linux:eap8-netty-codec-dns, p-cpe:/a:redhat:enterprise_linux:eap8-netty-codec-http, p-cpe:/a:redhat:enterprise_linux:eap8-netty-codec-socks, p-cpe:/a:redhat:enterprise_linux:eap8-netty-codec, p-cpe:/a:redhat:enterprise_linux:eap8-netty-common, p-cpe:/a:redhat:enterprise_linux:eap8-netty-handler-proxy, p-cpe:/a:redhat:enterprise_linux:eap8-netty-handler, p-cpe:/a:redhat:enterprise_linux:eap8-netty-resolver-dns, p-cpe:/a:redhat:enterprise_linux:eap8-netty-resolver, p-cpe:/a:redhat:enterprise_linux:eap8-netty-transport-classes-epoll, p-cpe:/a:redhat:enterprise_linux:eap8-netty-transport-native-epoll, p-cpe:/a:redhat:enterprise_linux:eap8-netty-transport-native-unix-common, p-cpe:/a:redhat:enterprise_linux:eap8-netty-transport, p-cpe:/a:redhat:enterprise_linux:eap8-netty, p-cpe:/a:redhat:enterprise_linux:eap8-nimbus-jose-jwt, p-cpe:/a:redhat:enterprise_linux:eap8-parsson, p-cpe:/a:redhat:enterprise_linux:eap8-relaxng-datatype, p-cpe:/a:redhat:enterprise_linux:eap8-rngom, p-cpe:/a:redhat:enterprise_linux:eap8-saaj-impl, p-cpe:/a:redhat:enterprise_linux:eap8-slf4j-api, p-cpe:/a:redhat:enterprise_linux:eap8-slf4j, p-cpe:/a:redhat:enterprise_linux:eap8-txw2, p-cpe:/a:redhat:enterprise_linux:eap8-undertow, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-elytron-tool, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-elytron, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-java-jdk17, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-java-jdk21, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-javadocs, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly-modules, p-cpe:/a:redhat:enterprise_linux:eap8-wildfly, p-cpe:/a:redhat:enterprise_linux:eap8-ws-commons-xmlschema, p-cpe:/a:redhat:enterprise_linux:eap8-xml-security, p-cpe:/a:redhat:enterprise_linux:eap8-xsom

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/22/2026

Vulnerability Publication Date: 4/15/2026

Reference Information

CVE: CVE-2026-10832, CVE-2026-14180, CVE-2026-15554, CVE-2026-15555, CVE-2026-15560, CVE-2026-15561, CVE-2026-15562, CVE-2026-15563, CVE-2026-15565, CVE-2026-15567, CVE-2026-3505, CVE-2026-44417, CVE-2026-46581, CVE-2026-49362, CVE-2026-49363, CVE-2026-49364, CVE-2026-49875, CVE-2026-50632, CVE-2026-54512, CVE-2026-54513, CVE-2026-54515, CVE-2026-55831, CVE-2026-55833, CVE-2026-56745, CVE-2026-56746, CVE-2026-5680, CVE-2026-57967, CVE-2026-59649, CVE-2026-59889, CVE-2026-59899, CVE-2026-62243, CVE-2026-68494, CVE-2026-69152, CVE-2026-73508, CVE-2026-85511, CVE-2026-86404

CWE: 120, 15, 184, 190, 290, 295, 306, 409, 444, 502, 611, 770, 772, 807, 829, 915, 94

RHSA: 2026:70228