Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:25125 - Security Advisory
Issued:
2026-06-10
Updated:
2026-06-10

RHSA-2026:25125 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: Red Hat JBoss Enterprise Application Platform 8.1.6 security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

A security update is now available for Red Hat JBoss Enterprise Application Platform 8.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat JBoss Enterprise Application Platform 8 is a platform for Java applications based on the WildFly application runtime.

This asynchronous patch is an update for Red Hat JBoss Enterprise Application Platform 8.1. See Release Notes for information about the most significant bug fixes and enhancements included in this release.

Security Fix(es):

  • jetty-server: Eclipse Jetty: Denial of Service due to unreleased JDK Inflater from compressed HTTP requests important (CVE-2026-1605)
  • undertow-core: Undertow: Request Smuggling via Malformed HTTP Request Headers (CVE-2026-28369)
  • undertow-core: Undertow: Request smuggling via inconsistent header parsing (CVE-2026-28368)
  • undertow-core: Undertow: Request smuggling via `\r\r\r` as a header block terminator (CVE-2026-28367)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

Before applying the update, make sure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258

Affected Products

  • JBoss Enterprise Application Platform 8.1 for RHEL 9 x86_64
  • JBoss Enterprise Application Platform 8.1 for RHEL 8 x86_64

Fixes

  • BZ - 2443260 - CVE-2026-28367 undertow: Undertow: Request smuggling via `\r\r\r` as a header block terminator
  • BZ - 2443261 - CVE-2026-28368 undertow: Undertow: Request smuggling via inconsistent header parsing
  • BZ - 2443262 - CVE-2026-28369 undertow: Undertow: Request Smuggling via Malformed HTTP Request Headers
  • BZ - 2444815 - CVE-2026-1605 org.eclipse.jetty/jetty-server: Eclipse Jetty: Denial of Service due to unreleased JDK Inflater from compressed HTTP requests

CVEs

  • CVE-2026-1605
  • CVE-2026-28367
  • CVE-2026-28368
  • CVE-2026-28369

References

  • https://access.redhat.com/security/updates/classification/#important
  • https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/8.1
  • https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/8.1/html/release_notes_for_red_hat_jboss_enterprise_application_platform_8.1/index
  • https://access.redhat.com/articles/7129481
Note: More recent versions of these packages may be available. Click a package name for more details.

JBoss Enterprise Application Platform 8.1 for RHEL 9

SRPM
eap8-activemq-artemis-2.40.0-7.redhat_00015.1.el9eap.src.rpm SHA-256: 1715d4023e48c332d99290839d76c1e17d6b8b141f3bba0052a7d9433dad1863
eap8-eap-product-conf-parent-801.6.1-1.GA_redhat_00001.1.el9eap.src.rpm SHA-256: c96e820de4dea02213c384f6ab1bb2537e91070bfa21e28189a9915ff8704e13
eap8-undertow-2.3.24-3.SP2_redhat_00001.1.el9eap.src.rpm SHA-256: 52f0c4be76c178ca8498f0669bf9bc800084f5395a7f964959ed62029b5cbbae
eap8-wildfly-8.1.6-7.GA_redhat_00010.1.el9eap.src.rpm SHA-256: 3a638996880f84e33f80f81627505d4bcd119c01cd045b009f86d69a1cfafced
x86_64
eap8-activemq-artemis-2.40.0-7.redhat_00015.1.el9eap.noarch.rpm SHA-256: b953a7f2473df242667fe096beeb3d19267e024b67ec90d3d78f42a758a65056
eap8-activemq-artemis-cli-2.40.0-7.redhat_00015.1.el9eap.noarch.rpm SHA-256: 4ddcfb775a6541a1b434e057f775f45e0707f472d942a878d1e8f9f9dd88ecd3
eap8-activemq-artemis-commons-2.40.0-7.redhat_00015.1.el9eap.noarch.rpm SHA-256: 78044b8e3b8f8c8749367ffc607bcc6da307c0f0c82c3eef28987968dfe28edb
eap8-activemq-artemis-core-client-2.40.0-7.redhat_00015.1.el9eap.noarch.rpm SHA-256: 91412e090790fa99db176ab0f471d375769d1fb5e11f2973b71287bd2fe0af3f
eap8-activemq-artemis-dto-2.40.0-7.redhat_00015.1.el9eap.noarch.rpm SHA-256: 4589faf8d3dac399dbb7ebf4050801fedbca7347acd30b73de84223bfc091056
eap8-activemq-artemis-hornetq-protocol-2.40.0-7.redhat_00015.1.el9eap.noarch.rpm SHA-256: b4663a9e5690a8efd9be5e9e0bb22d362bb36aef28a92afc4a56afc6dc17afaf
eap8-activemq-artemis-hqclient-protocol-2.40.0-7.redhat_00015.1.el9eap.noarch.rpm SHA-256: dffc2b07336435c088190412e1dbe6d74d82d56181140ff4a320fa72ac1d14b9
eap8-activemq-artemis-jakarta-client-2.40.0-7.redhat_00015.1.el9eap.noarch.rpm SHA-256: 7062d2e8f54cd8e5ab27796959edcad7793b8dd1286f000ec726d716fa132045
eap8-activemq-artemis-jakarta-ra-2.40.0-7.redhat_00015.1.el9eap.noarch.rpm SHA-256: ad4f3cc0575642d5603fb955a839678b0151f9e1bbe46666037be045f6ab81de
eap8-activemq-artemis-jakarta-server-2.40.0-7.redhat_00015.1.el9eap.noarch.rpm SHA-256: 564fcfc7ff2ed9c093821ad8ac286bae5bf6b156ec467dcb0d395c9c3e16affb
eap8-activemq-artemis-jakarta-service-extensions-2.40.0-7.redhat_00015.1.el9eap.noarch.rpm SHA-256: 018cacd07d490091027144ab741214bce2dd4a2fab23b13ffc7a842b96dc58ee
eap8-activemq-artemis-jdbc-store-2.40.0-7.redhat_00015.1.el9eap.noarch.rpm SHA-256: f34c7d89c5fd3033c03b3791df410eb74c682cfa7b4a2e612c726336fc9af39a
eap8-activemq-artemis-journal-2.40.0-7.redhat_00015.1.el9eap.noarch.rpm SHA-256: 5beb68270a2ee152a2694f0758452880c9d24efb05fef9964af3301912b65eb1
eap8-activemq-artemis-selector-2.40.0-7.redhat_00015.1.el9eap.noarch.rpm SHA-256: fd67795c952230267f53f0da55bb355688acbe3b698affe82484d1b9f0941261
eap8-activemq-artemis-server-2.40.0-7.redhat_00015.1.el9eap.noarch.rpm SHA-256: 824c3e608a5cfc36ad26cf1545fbc62dfcef909f5bdd94ad04b81969e3b0eca0
eap8-eap-product-conf-parent-801.6.1-1.GA_redhat_00001.1.el9eap.noarch.rpm SHA-256: 4e9989e445a4016f882563c6838f1dfe9c10eae2662b0bed42a1ef64be4b789f
eap8-eap-product-conf-wildfly-ee-feature-pack-801.6.1-1.GA_redhat_00001.1.el9eap.noarch.rpm SHA-256: 0b80da1f8274e3fcf7ae3dfb078544fc24f492945cc6e16cd3d3ea64a737b3dd
eap8-undertow-2.3.24-3.SP2_redhat_00001.1.el9eap.noarch.rpm SHA-256: 5f792d7a2cc145d16c585e2d276ae16d510f3ea4dc604afd57acebe0b0ce703a
eap8-wildfly-8.1.6-7.GA_redhat_00010.1.el9eap.noarch.rpm SHA-256: d178f14272c49130dffab0b3bb6922933ca6abd552884c858e3560bf1630128d
eap8-wildfly-java-jdk17-8.1.6-7.GA_redhat_00010.1.el9eap.noarch.rpm SHA-256: 5d8c60fcbfd74689322e09d4e18bcc3bef180c0112f4347fbec4b6e8be7f43f1
eap8-wildfly-java-jdk21-8.1.6-7.GA_redhat_00010.1.el9eap.noarch.rpm SHA-256: dd402e3c10e71df6e5fe1b1236e3a039391d4ae8b18392eefcb14e7be39a9c6e
eap8-wildfly-modules-8.1.6-7.GA_redhat_00010.1.el9eap.noarch.rpm SHA-256: 4dd1ec9acf3ab4a93c9bd7509df7bd1820032ab9984f85a4ec72d836a69cfa2e

JBoss Enterprise Application Platform 8.1 for RHEL 8

SRPM
eap8-activemq-artemis-2.40.0-7.redhat_00015.1.el8eap.src.rpm SHA-256: 838f6f35e4139500e30e36c71ff1638efd6b476bed06a49d6c91ab47b384defc
eap8-eap-product-conf-parent-801.6.1-1.GA_redhat_00001.1.el8eap.src.rpm SHA-256: 9a825dae43a53bb2d292310255c59255426f613715f33b8518ae7363c8292ddf
eap8-undertow-2.3.24-3.SP2_redhat_00001.1.el8eap.src.rpm SHA-256: 8335e232e33ce3fdb4654366bccf0e665bffeac12efd685b99bb0f8e0216df3e
eap8-wildfly-8.1.6-7.GA_redhat_00010.1.el8eap.src.rpm SHA-256: 566150cc7727691726fec84220462ec0dfa22d9fe9fd974dd7d892f744954b22
x86_64
eap8-activemq-artemis-2.40.0-7.redhat_00015.1.el8eap.noarch.rpm SHA-256: c21c39b4d4f8f8813ac3c8b871edba7459e248f112e6ce35210f5df8e39491af
eap8-activemq-artemis-cli-2.40.0-7.redhat_00015.1.el8eap.noarch.rpm SHA-256: b1319cde023893c3065fb464cbc7abe199a2612a3ada5d473ab1c696fcb0d3c2
eap8-activemq-artemis-commons-2.40.0-7.redhat_00015.1.el8eap.noarch.rpm SHA-256: 87af6a55d13ec7fe6d0b1182ba1f7c76ffc691b22ae9012893a07128ca1a1e58
eap8-activemq-artemis-core-client-2.40.0-7.redhat_00015.1.el8eap.noarch.rpm SHA-256: 2186969c745e2830a37dcc5682389334e0f7a458059a905ce1fc7f4b21ea5551
eap8-activemq-artemis-dto-2.40.0-7.redhat_00015.1.el8eap.noarch.rpm SHA-256: f25a0450ffb21cd1fbdcf51e1f05e4782e1c6335690bfbbba09a933d3fbc063c
eap8-activemq-artemis-hornetq-protocol-2.40.0-7.redhat_00015.1.el8eap.noarch.rpm SHA-256: f321c8cf685e43c5962878508d88d65b7c794597915bbd0f4f7fc8e6b069f9e0
eap8-activemq-artemis-hqclient-protocol-2.40.0-7.redhat_00015.1.el8eap.noarch.rpm SHA-256: 2b45bb1b1a13cfc05d7ed0e36ab1420331001b468242e9b04a977c30c1c5f34f
eap8-activemq-artemis-jakarta-client-2.40.0-7.redhat_00015.1.el8eap.noarch.rpm SHA-256: 50a26ef4a62d75c0c3914f7c8c3c9979243a75306ee8740103e32dc8ae861728
eap8-activemq-artemis-jakarta-ra-2.40.0-7.redhat_00015.1.el8eap.noarch.rpm SHA-256: 9dcc4fcfc72b410d495ffda725c592b46783780925125ae8612bad6a11967d06
eap8-activemq-artemis-jakarta-server-2.40.0-7.redhat_00015.1.el8eap.noarch.rpm SHA-256: d39a8e1ef501e250a81fc1130e70e88eb2ea6f9f12b75e0a36e5bd80aa85c89a
eap8-activemq-artemis-jakarta-service-extensions-2.40.0-7.redhat_00015.1.el8eap.noarch.rpm SHA-256: 7974db6743114c506641fee73c935d04299c934cf152cefdfa458d5cbfdc2236
eap8-activemq-artemis-jdbc-store-2.40.0-7.redhat_00015.1.el8eap.noarch.rpm SHA-256: 7aaf56c71e0f592c23609f32db58003a2cf45c2e53529a3fbc6fa9728301d01c
eap8-activemq-artemis-journal-2.40.0-7.redhat_00015.1.el8eap.noarch.rpm SHA-256: 0bfb809432d66c2da74487b23d3a3112f5524669cdbffb759afd5198906b9495
eap8-activemq-artemis-selector-2.40.0-7.redhat_00015.1.el8eap.noarch.rpm SHA-256: 07ad5fb0a899519440e1845e75a6a3c180a4c0abdb837a33715100cc074fcce0
eap8-activemq-artemis-server-2.40.0-7.redhat_00015.1.el8eap.noarch.rpm SHA-256: f710b98e66728651fa41bac38316ea744a00074ca2e4e5167d32986d8565e46e
eap8-eap-product-conf-parent-801.6.1-1.GA_redhat_00001.1.el8eap.noarch.rpm SHA-256: 8fea690b2bffd5bf23774c54657869894c9f97c4693e628202c36619189f7943
eap8-eap-product-conf-wildfly-ee-feature-pack-801.6.1-1.GA_redhat_00001.1.el8eap.noarch.rpm SHA-256: 392629da4cae0ab7a55d82e8ed33ae4a52ebc26685c318474c13d26501182d40
eap8-undertow-2.3.24-3.SP2_redhat_00001.1.el8eap.noarch.rpm SHA-256: 0f93dce69bf5dc75e2ee177b074f583adffc628bfffad502b236ebee472e235f
eap8-wildfly-8.1.6-7.GA_redhat_00010.1.el8eap.noarch.rpm SHA-256: ed22b821173f316091618c580613758f5f853d5abc44ae850c3850c39fb38b7b
eap8-wildfly-java-jdk17-8.1.6-7.GA_redhat_00010.1.el8eap.noarch.rpm SHA-256: c255df608676e097c633fc09011c1b3b4dab1af1758719a3d95205f0d26df816
eap8-wildfly-java-jdk21-8.1.6-7.GA_redhat_00010.1.el8eap.noarch.rpm SHA-256: 0b05d15fcf351a39483985a7d7fdb49bfe102ae4f034c40dc9401fc77485ea63
eap8-wildfly-modules-8.1.6-7.GA_redhat_00010.1.el8eap.noarch.rpm SHA-256: 12d80b74f5c410c44f94d31b26ffa69052ccdcb7cb8952622bcab5c1460efa8d

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility