What is CVE-2026-15561?
CVE-2026-15561 is a flaw in EAP's Undertow HTTP/1.1 chunked-transfer decoder where missing limits on size and count allow an unauthenticated attacker to force the JVM into an OutOfMemory error. This results in a Denial of Service by stopping all deployments on the affected listener. Affected systems should be patched or monitored until a fix is applied.
Azərbaycanca: CVE-2026-15561 zəifliyi EAP-in Undertow HTTP/1.1 chunked-transfer dekoderində limitlərin olmaması səbəbindən autentifikasiya olunmamış hücumçunun JVM-i OutOfMemory xətasına sürükləməsinə imkan verir. Bu, listener üzərindəki bütün deployment-ləri dayandıraraq Denial of Service (DoS) vəziyyəti yaradır. Təhlükəsizlik yaması tətbiq edilənə qədər təsirlənmiş serverlər izlənməlidir.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: EAP
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.