Skip to content
Red HatCVE-2026-5680

Red Hat Undertow. A remote attacker: resource exhaustion

High7.5CVE-2026-5680 · Published Aug 27, 2026 · updated Sep 22, 2026

A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead to excessive memory consumption due to the PerMessageDeflateFunction.largerBuffer() method using exponential doubling, resulting in a Denial of Service (DoS) for the affected application.

Red Hat advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat gdk-pixbuf.: out-of-bounds write
Medium4.7Aug 27
Red Hat rsyslog: buffer overflow
High7.5Aug 27
Red Hat Satellite 6: insecure direct object reference
Medium6.5Aug 27
Red Hat Satellite 6: insecure direct object reference
Medium5.4Aug 27
A flaw was found in the ipa_getkeytab module of the community.general Ansible...
Medium5.5Aug 26
Red Hat Seattle FilmWorks plugin: integer overflow
Medium5.5Aug 26

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.