What is CVE-2026-15565?
CVE-2026-15565 is a vulnerability in Undertow where a remote attacker can trigger an Out of Memory condition on websocket endpoints without authentication on any @ServerEndpoint class having at least one @OnMessage method. This allows a Denial of Service attack using only a standard WebSocket handshake. Users should apply the security update for Undertow.
Azərbaycanca: CVE-2026-15565, Undertow veb serverində autentifikasiya tələb etməyən və @OnMessage metodu olan istənilən @ServerEndpoint klassı üzərindən WebSocket əl sıxışması ilə yaddaşın tükənməsinə (Out of Memory) səbəb olan boşluqdur. Uzaqdan hücumçu standart WebSocket bağlantısı ilə xidmətə qarşı Denial of Service hücumu həyata keçirə bilər. Bu boşluğun aradan qaldırılması üçün Undertow-un təhlükəsizlik yeniləməsini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
What type of attack can be performed using CVE-2026-15565?
CVE-2026-15565 allows a remote attacker to carry out a Denial of Service attack using only a standard WebSocket handshake.
Which Undertow components are affected by this vulnerability?
The vulnerability affects WebSocket endpoints without authentication on any @ServerEndpoint class having at least one @OnMessage method.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.