Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 8.1.6 security update
🔗 CVE IDs covered (13)
📋 Description
CVE-2025-14813 — bouncycastle: BC-JAVA: GOSTCTR implementation unable to process more than 255 blocks correctly CVE-2025-23368 — org.wildfly.core:wildfly-elytron-integration: Wildfly Elytron Brute Force Attack via CLI CVE-2026-0636 — bouncycastle: BC-JAVA: LDAP injection vulnerability in LDAPStoreHelper.java CVE-2026-3505 — bouncycastle: BC-JAVA: unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion CVE-2026-5588 — bouncycastle: BC-JAVA: PKIX draft CompositeVerifier accepts empty signature sequence as valid CVE-2026-5598 — bouncycastle: BC-JAVA: private key leakage via non-constant time comparisons CVE-2026-26996 — minimatch: minimatch: Denial of Service via specially crafted glob patterns CVE-2026-27446 — org.apache.artemis:artemis-server: org.apache.activemq:artemis-server: Apache Artemis, Apache ActiveMQ Artemis: Message injection and exfiltration due to missing authentication CVE-2026-27727 — com.mchange/mchange-commons-java: mchange-commons-java: Arbitrary code execution via JNDI dereferencing of crafted objects CVE-2026-27830 — c3p0: c3p0: Arbitrary Code Execution via deserialization of crafted objects CVE-2026-27904 — minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions CVE-2026-33870 — io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values CVE-2026-33871 — netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood
🔗 References (45)
- selfhttps://access.redhat.com/errata/RHSA-2026:18059
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/8.1
- externalhttps://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/8.1/html/release_notes_for_red_hat_jboss_enterprise_application_platform_8.1/index
- externalhttps://access.redhat.com/articles/7137769
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2337621
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2441268
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2442671
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2442908
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2442922
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2444320
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2452453
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2452456
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2458634
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2458635
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2458638
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2458640
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2458641
- externalhttps://issues.redhat.com/browse/JBEAP-29032
- externalhttps://issues.redhat.com/browse/JBEAP-31314
- externalhttps://issues.redhat.com/browse/JBEAP-31468
- externalhttps://issues.redhat.com/browse/JBEAP-31868
- externalhttps://issues.redhat.com/browse/JBEAP-31874
- externalhttps://issues.redhat.com/browse/JBEAP-32025
- externalhttps://issues.redhat.com/browse/JBEAP-32028
- externalhttps://issues.redhat.com/browse/JBEAP-32064
- externalhttps://issues.redhat.com/browse/JBEAP-32078
- externalhttps://issues.redhat.com/browse/JBEAP-32084
- externalhttps://issues.redhat.com/browse/JBEAP-32123
- externalhttps://issues.redhat.com/browse/JBEAP-32209
- externalhttps://issues.redhat.com/browse/JBEAP-32212
- externalhttps://issues.redhat.com/browse/JBEAP-32266
- externalhttps://issues.redhat.com/browse/JBEAP-32293
- externalhttps://issues.redhat.com/browse/JBEAP-32295
- externalhttps://issues.redhat.com/browse/JBEAP-32339
- externalhttps://issues.redhat.com/browse/JBEAP-32350
- externalhttps://issues.redhat.com/browse/JBEAP-32415
- externalhttps://issues.redhat.com/browse/JBEAP-32481
- externalhttps://issues.redhat.com/browse/JBEAP-32486
- externalhttps://issues.redhat.com/browse/JBEAP-32544
- externalhttps://issues.redhat.com/browse/JBEAP-32601
- externalhttps://issues.redhat.com/browse/JBEAP-32687
- externalhttps://issues.redhat.com/browse/JBEAP-32755
- externalhttps://issues.redhat.com/browse/JBEAP-32773
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_18059.json