Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.1.16 security update
🔗 CVE IDs covered (7)
📋 Description
CVE-2026-27727 — com.mchange/mchange-commons-java: mchange-commons-java: Arbitrary code execution via JNDI dereferencing of crafted objects CVE-2026-27830 — c3p0: c3p0: Arbitrary Code Execution via deserialization of crafted objects CVE-2026-42578 — netty: io.netty/netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation CVE-2026-42581 — netty: io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers CVE-2026-42583 — netty: io.netty/netty-codec-compression: io.netty/netty-codec: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoder CVE-2026-42584 — netty: io.netty/netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion CVE-2026-42585 — netty: io.netty/netty-codec-http: Netty: Request smuggling via malformed Transfer-Encoding parsing
🎯 Affected products14
- Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server
- eap7-hibernate-0:5.1.17-5.Final_redhat_00006.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server
- eap7-hibernate-0:5.1.17-5.Final_redhat_00006.1.ep7.el7.src as a component of Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server
- eap7-hibernate-core-0:5.1.17-5.Final_redhat_00006.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server
- eap7-hibernate-entitymanager-0:5.1.17-5.Final_redhat_00006.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server
- eap7-hibernate-envers-0:5.1.17-5.Final_redhat_00006.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server
- eap7-hibernate-infinispan-0:5.1.17-5.Final_redhat_00006.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server
- eap7-hibernate-java8-0:5.1.17-5.Final_redhat_00006.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server
- eap7-netty-0:4.1.63-4.Final_redhat_00005.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server
- eap7-netty-0:4.1.63-4.Final_redhat_00005.1.ep7.el7.src as a component of Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server
- eap7-netty-all-0:4.1.63-4.Final_redhat_00005.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server
- eap7-wildfly-0:7.1.16-1.GA_redhat_00002.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server
- eap7-wildfly-0:7.1.16-1.GA_redhat_00002.1.ep7.el7.src as a component of Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server
- eap7-wildfly-modules-0:7.1.16-1.GA_redhat_00002.1.ep7.el7.noarch as a component of Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Server
✅ Remediation
Before applying this update, ensure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Applications utilizing Netty's HttpProxyHandler must ensure that any user-controlled input used to populate outbound headers is rigorously sanitized to prevent CRLF injection. If comprehensive input sanitization cannot be implemented, restricting network access to the application that uses the HttpProxyHandler can reduce the attack surface. Workaround: To mitigate this issue, configure any reverse proxies or load balancers in front of Netty to either reject HTTP/1.0 requests containing both Transfer-Encoding: chunked and Content-Length headers, or to explicitly prioritize the Transfer-Encoding header over Content-Length for HTTP/1.0 traffic. This ensures consistent interpretation of message boundaries and prevents request smuggling attacks. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (15)
- selfhttps://access.redhat.com/errata/RHSA-2026:73976
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.1
- externalhttps://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.1/html-single/installation_guide/index
- externalhttps://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.1/html-single/7.1.0_release_notes/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2442671
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2442908
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2477219
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2477224
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2477226
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2477227
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2477232
- externalhttps://issues.redhat.com/browse/JBEAP-33911
- externalhttps://issues.redhat.com/browse/JBEAP-34006
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_73976.json