RHSA-2026:3951HighCVSS 7.5

Red Hat Security Advisory: JBoss EAP XP 5.0 Update 4.0 release. See references for release notes.

Published
March 5, 2026
Last Modified
May 26, 2026

🔗 CVE IDs covered (3)

CVE-2025-58057 · pendingCVE-2025-66566CVE-2026-1002 · pending

📋 Description

CVE-2025-58057 — netty-codec: netty-codec-compression: Netty's BrotliDecoder is vulnerable to DoS via zip bomb style attack CVE-2025-66566 — lz4-java: lz4-java: Information Disclosure via Insufficient Output Buffer Clearing CVE-2026-1002 — io.vertx/vertx-core: static handler component cache can be manipulated to deny the access to static files

🔗 References (9)