VendorsRed Hatjboss_enterprise_application_platform_expansion_packall versions
Vulnerabilities

Red Hat JBoss Enterprise Application Platform (EAP) Expansion Pack

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

23CVEs
CVE-2025-12543
Undertow-core: undertow http server fails to reject malformed host headers leading to potential cache poisoning and ssrf
Published 2026-01-07 · Modified
9.6EPSS 0.014
CVE-2026-28367
Undertow: undertow: request smuggling via `\r\r\r` as a header block terminator
Published 2026-03-27 · Modified
9.1EPSS 0.009
CVE-2026-28369
Undertow: undertow: request smuggling via malformed http request headers
Published 2026-03-27 · Modified
9.1EPSS 0.009
CVE-2026-28368
Undertow: undertow: request smuggling via inconsistent header parsing
Published 2026-03-27 · Modified
9.1EPSS 0.009
CVE-2026-41731
In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization
Published 2026-06-09 · Analyzed
8.1EPSS 0.006
CVE-2026-3009
Org.keycloak/keycloak-services: improper enforcement of disabled identity provider in identitybrokerservice (authentication bypass)
Published 2026-03-05 · Modified
8.1EPSS 0.005
CVE-2026-15573
Keycloak-services: keycloak-services: authorization bypass via unnormalized uri matching in pathmatcher
Published 2026-08-05 · Modified
8.1EPSS 0.005
CVE-2026-16102
Keycloak-services: keycloak-services: default dcr policy allows role forgery via user property mappers
Published 2026-08-05 · Modified
8.1EPSS 0.005
CVE-2026-18967
Keycloak-services: keycloak-services: saml onetimeuse assertion replay in idp-initiated broker flow
Published 2026-08-06 · Analyzed
8.1EPSS 0.002
CVE-2025-9784
Undertow: undertow madeyoureset http/2 ddos vulnerability
Published 2025-09-02 · Modified
7.5EPSS 0.023
CVE-2023-1108
Undertow: infinite loop in sslconduit during close
Published 2023-09-14 · Modified
7.5EPSS 0.018
CVE-2022-0853
A flaw was found in JBoss-client. The vulnerability occurs due to a memory leak on the JBoss client-side, when using UserTransaction repeatedly and leads to information leakage vulnerability.
Published 2022-03-11 · Modified
7.5EPSS 0.015
CVE-2022-1278
A flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload may contain.
Published 2022-09-13 · Modified
7.5EPSS 0.009
CVE-2023-4503
Eap-galleon: custom provisioning creates unsecured http-invoker
Published 2024-02-06 · Modified
7.5EPSS 0.007
CVE-2026-3121
Keycloak: org.keycloak/keycloak-services: keycloak: privilege escalation via manage-clients permission
Published 2026-03-26 · Modified
7.2EPSS 0.005
CVE-2026-4366
Keycloak-services: blind server-side request forgery (ssrf) via http redirect handling in keycloak
Published 2026-03-18 · Modified
5.8EPSS 0.004
CVE-2025-5731
Infinispan: credential leakage in infinispan cli
Published 2025-06-26 · Modified
5.5EPSS 0.002
CVE-2026-16093
Keycloak-services: keycloak-services: required signed-jwt assertion policy can be bypassed with unsigned assertion headers
Published 2026-07-17 · Modified
5.4EPSS 0.004
CVE-2021-3642
A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnerability is confidentiality.
Published 2021-08-05 · Modified
5.3EPSS 0.008
CVE-2021-20250
A flaw was found in wildfly. The JBoss EJB client has publicly accessible privileged actions which may lead to information disclosure on the server it is deployed on. The highest threat from this vulnerability is to data confidentiality.
Published 2021-05-13 · Modified
4.3EPSS 0.007
CVE-2026-14209
Keycloak-admin-ui: keycloak-admin-ui:admin ui extension brute-force-user endpoint bypasses fgapv2 user view restrictions
Published 2026-06-30 · Modified
4.3EPSS 0.004
CVE-2026-15945
Keycloak-services: keycloak-services: group hierarchy search discloses hidden parent groups under fgap v2
Published 2026-07-16 · Modified
4.3EPSS 0.003
CVE-2026-4874
Org.keycloak.protocol.oidc.grants: org.keycloak.services.managers: keycloak: server-side request forgery via oidc token endpoint manipulation
Published 2026-03-26 · Modified
3.1EPSS 0.003