Is JBoss EAP impacted by CVE-2026-5598 and what is the resolution?
Issue
- Security scans find a new critical CVE-2026-5598 issue applies JBoss EAP through its included bouncy castle library. What is the resolution to this?
- Status of CVE-2026-5598 and CVE-2025-14813 on JBoss EAP 8.1.x
Environment
- Red Hat JBoss Enterprise Application Platform (EAP)
- 7.x
- 8.x
- Bouncy Castle
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.