Red Hat JBoss Enterprise Application Platform
Red Hat JBoss Enterprise Application Platform (JBoss EAP) delivers enterprise-grade security, performance, and scalability in any environment. Red Hat supports deploying JBoss EAP on-premise, on hyperscalers, and on OpenShift. Whether on-premise, virtual, or in private, public, or hybrid clouds, JBoss EAP can help you deliver apps faster, everywhere. Customers of the Red Hat Ansible Automation Platform can take advantage of the Red Hat Ansible Certified Content Collections for Runtimes to automate the deployment of various runtimes products and components, including JBoss EAP 7.4.
browse_doc
latest_security
| severity | advisory_cve | synopsis | date |
|---|---|---|---|
| severity Important | advisory_cveCVE-2026-73643 | synopsis A flaw was found in js-yaml, a JavaScript YAML parser. A remote attacker could exploit this vulnerability by providing specially crafted YAML input containing nested flow collections. This can lead to exponential parsing time when the application processes untrusted input, consuming excessive CPU resources. This resource exhaustion can block the Node.js event loop and cause a Denial of Service (DoS) for the affected process. | date |
| severity Important | advisory_cve(RHSA-2026:50085) Important: Red Hat JBoss Enterprise Application Platform 8.1.7.1 XP 6.0.5.1 release | synopsis Important: Red Hat JBoss Enterprise Application Platform 8.1.7.1 XP 6.0.5.1 release | date |
| severity Important | advisory_cve(RHSA-2026:49701) Important: Red Hat JBoss Enterprise Application Platform 8.1.7 security update | synopsis Important: Red Hat JBoss Enterprise Application Platform 8.1.7 security update | date |
| severity Important | advisory_cveCVE-2026-67312 | synopsis A flaw was found in axios, a popular JavaScript library. An attacker can exploit this vulnerability by providing malicious form data containing deeply nested field names. This input triggers uncontrolled recursion within the formDataToJSON function, which is responsible for processing form data. The excessive recursion exhausts the application's JavaScript call stack, leading to a denial of service for the affected request or, in some cases, causing the entire application process to terminate. | date |
| severity Moderate | advisory_cve(RHSA-2026:42098) Moderate: Red Hat JBoss Enterprise Application Platform 8.1.7 XP 6.0.5.GA release | synopsis Moderate: Red Hat JBoss Enterprise Application Platform 8.1.7 XP 6.0.5.GA release | date |
top_resources
Knowledgebase
Access articles and solutions to find answers to your questions.
Troubleshooting
Connect to the right information to self-solve issues quickly and efficiently.
Lifecycle
View the various levels of maintenance for each release of a product over a period from initial release to the end of maintenance.
Red Hat Ansible Certified Content Collections for Runtimes
Automate the deployment of various runtimes products and components.