Red Hat JBoss Web Server
Red Hat JBoss Web Server combines the world's most deployed web server (Apache) with the top servlet engine and the best support in middleware. Customers of the Red Hat Ansible Automation Platform can take advantage of the Red Hat Ansible Certified Content Collections for Runtimes to automate the deployment of various runtimes products and components.
browse_doc
Supported Configurations and IntegrationsSupported Configurations and Component Details
Installation GuideInstalling
HTTP Connectors and Load Balancing GuideConfiguring and maintaining
Red Hat JBoss Web Server for OpenShiftOpenShift Container Platform
latest_security
| severity | advisory_cve | synopsis | date |
|---|---|---|---|
| severity Moderate | advisory_cveCVE-2026-68079 | synopsis A flaw was found in Apache CXF's DefaultEncryptingCodeDataProvider. This vulnerability allows a remote attacker to redeem a captured authorization code an unlimited number of times. The flaw exists due to an issue in the `removeCodeGrant` functionality, which fails to properly invalidate used authorization codes. This can lead to unauthorized access or session hijacking, violating the security principle that authorization codes should only be used once. | date |
| severity Low | advisory_cveCVE-2026-57817 | synopsis A flaw was found in Apache CXF. When operating in the OpenID Connect Hybrid Flow, Apache CXF does not enforce the validation of the `c_hash` parameter. This vulnerability allows a remote attacker, through a non-compliant or misconfigured Identity Provider (IdP), to perform Authorization Code Substitution/Injection attacks. Such an attack could lead to unauthorized access or session hijacking. | date |
| severity Important | advisory_cveCVE-2026-68494 | synopsis A flaw was found in jackson-core. A remote attacker can exploit an incomplete fix in the non-blocking JSON parser by streaming specially crafted JSON data in small chunks. This bypasses the intended number length constraint, causing the parser to accumulate excessive memory per connection. This uncontrolled memory growth can lead to a denial of service (DoS) by exhausting the Java Virtual Machine (JVM) heap. | date |
| severity Moderate | advisory_cveCVE-2026-59888 | synopsis A flaw was found in jackson-databind. When Java Records use a PropertyNamingStrategy, an attacker can bypass the @JsonIgnore annotation during deserialization. This allows a renamed JSON key to be assigned to a Record constructor parameter, even if it was intended to be ignored. Consequently, an untrusted client could set internal or privileged components from external input, potentially leading to unauthorized modification or disclosure of sensitive data. | date |
| severity Important | advisory_cveCVE-2026-55957 | synopsis A flaw was found in Apache Tomcat. When the JNDIRealm was configured to authenticate binds using GSSAPI, an attacker could exploit a missing critical step in the authentication process. This allowed the attacker to bypass password verification and authenticate without providing the correct password, leading to unauthorized access. | date |
top_resources
Lifecycle
View the various levels of maintenance for each release of a product over a period from initial release to the end of maintenance.
Troubleshooting
Connect to the right information to self-solve issues quickly and efficiently.
Supported configurations
See your Red Hat-provided production or development support for supported configurations.
Red Hat Ansible Certified Content Collections for Runtimes
Automate the deployment of various runtimes products and components.