Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2537▼ 356 respecto a la semana anterior
Críticas / altas1341▲ 75 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
52 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.9) | 0.42% | — | Wildfly Elytron-asn1AI | 18/9/2026 | 29/9/2026 | A flaw was found in the DERDecoder class within wildfly-elytron-asn1. A remote attacker can exploit this resource exhaustion vulnerability by sending a specially crafted DER (Distinguished Encoding Rules) payload. The decoder attempts to allocate excessive memory based on an inflated length value without proper… | |
| Pendiente de análisis | Alta (7.5) | 0.58% | — | Redhat Jboss EAPAIRedhat WildflyAIRedhat UndertowAI | 31/8/2026 | 10/9/2026 | Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how Undertow handles WebSocket connections. Specifically, certain configuration limits like message buffer sizes and session timeouts cannot be adjusted and default to being unlimited. This allows a remote attacker to send… | |
| Pendiente de análisis | Alta (7.4) | 0.56% | — | Wildfly ElytronAI | 20/8/2026 | 21/9/2026 | A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth characters to ASCII equivalents. A remote attacker can more easily guess affected passwords by using an ASCII-only dictionary against accounts whose passwords were intended to include… | |
| Pendiente de análisis | Media (5.3) | 1.0% | — | WildflyAIJboss EAPAIRedhat UndertowAI | 11/8/2026 | 22/9/2026 | A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to handle chunked transfer encoding. The issue occurs because the parser uses a single internal variable to store both the remaining chunk size and state flags. By sending a specially crafted request with… | |
| Pendiente de análisis | Alta (7.5) | 0.55% | — | WildflyAI | 11/8/2026 | 25/9/2026 | A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2Util's GSS token decoder reads an attacker-controlled length field without bounds checking and attempts to allocate a byte array of that size. | |
| Pendiente de análisis | Media (6.5) | 0.52% | — | Wildfly CoreAI | 11/8/2026 | 14/8/2026 | A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a malicious archive file from an untrusted source. This is achieved by leveraging WildFly libraries to craft a Java project that allows an HTTP POST request to upload and deploy the malicious archive. This… | |
| Pendiente de análisis | Media (4.9) | 0.60% | — | Wildfly-coreAI | 11/8/2026 | 14/8/2026 | A flaw was found in wildfly-core. A remote user authenticated as an administrative user can inject a malformed payload into the Inet Address field through the Management Model. This injection causes the server to crash and become unrecoverable, as the payload is written into the standalone.xml configuration file.… | |
| Pendiente de análisis | Media (4.4) | 1.1% | — | Wildfly CoreAI | 4/8/2026 | 6/8/2026 | — | |
| Aplazada | Crítica (9.3) | 1.1% | — | Care Everywhere GatewayAIWildflyAI | 29/7/2026 | 30/7/2026 | Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows unauthenticated remote attackers to gain administrative access by using default credentials identical across all installations. Attackers can authenticate to the exposed… | |
| Aplazada | Media (6.2) | 1.0% | — | WildflyAIRedhat Jboss Enterprise Application PlatformAIJboss MarshallingAI | 7/4/2025 | 19/8/2026 | A security flaw exists in WildFly and JBoss Enterprise Application Platform (EAP) within the Enterprise JavaBeans (EJB) remote invocation mechanism. This vulnerability stems from untrusted data deserialization handled by JBoss Marshalling. This flaw allows an attacker to send a specially crafted serialized object,… | |
| Modificada | Alta (8.1) | 0.89% | — | Redhat Wildfly CoreRedhat Data GridRedhat Jboss Enterprise Application Platform | 4/3/2025 | 14/9/2026 | A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks via CLI. | |
| Modificada | Media (6.5) | 0.77% | — | Redhat Jboss Enterprise Application PlatformRedhat Wildfly | 30/1/2025 | 18/9/2026 | A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role Based Access Control provider, a user without the required privileges can suspend or resume the server. A user with a Monitor or Auditor role is supposed to… | |
| Aplazada | Media (4.1) | 0.28% | — | WildflyAI | 2/5/2024 | 24/9/2026 | A vulnerability was found in Wildfly’s management interface. Due to the lack of limitation of sockets for the management interface, it may be possible to cause a denial of service hitting the nofile limit as there is no possibility to configure or set a maximum number of connections. | |
| Modificada | Media (6.5) | 0.83% | — | Redhat Jboss Enterprise Application PlatformRedhat Wildfly Core | 8/11/2023 | 23/9/2026 | A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possible sensitive information from the Wildfly system. This issue could allow a malicious user to access the system and obtain possible sensitive information from the system. | |
| Modificada | Alta (7.4) | 0.58% | — | Redhat Wildfly ElytronRedhat Jboss Enterprise Application Platform | 13/1/2023 | 17/6/2026 | wildfly-elytron: possible timing attacks via use of unsafe comparator. A flaw was found in Wildfly-elytron. Wildfly-elytron uses java.util.Arrays.equals in several places, which is unsafe and vulnerable to timing attacks. To compare values securely, use java.security.MessageDigest.isEqual instead. This flaw allows an… | |
| Modificada | Media (5.3) | 0.69% | — | Jenkins Wildfly Deployer | 21/9/2022 | 17/6/2026 | Jenkins WildFly Deployer Plugin 1.0.2 and earlier implements functionality that allows agent processes to read arbitrary files on the Jenkins controller file system. | |
| Modificada | Alta (7.5) | 0.86% | — | Redhat WildflyRedhat AMQRedhat AMQ OnlineRedhat Integration Camel K+4 | 13/9/2022 | 17/6/2026 | A flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload may contain. | |
| Modificada | Baja (3.3) | 0.96% | — | Redhat Descision ManagerRedhat Wildfly | 26/8/2022 | 17/6/2026 | A flaw was found in wildfly-core in all versions. If a vault expression is in the form of a single attribute that contains multiple expressions, a user who was granted access to the management interface can potentially access a vault expression they should not be able to access and possibly retrieve the item which was… | |
| Modificada | Alta (7.8) | 0.31% | — | Redhat Jboss Enterprise Application PlatformRedhat Single Sign-onRedhat Wildfly Core | 24/5/2022 | 17/6/2026 | A flaw was found in Wildfly. An incorrect JBOSS_LOCAL_USER challenge location when using the elytron configuration may lead to JBOSS_LOCAL_USER access to all users on the machine. The highest threat from this vulnerability is to confidentiality, integrity, and availability. This flaw affects wildfly-core versions… | |
| Modificada | Media (5.9) | 1.3% | — | Redhat IntegrationRedhat Jboss Enterprise Application PlatformRedhat Single Sign-onRedhat Undertow+4 | 24/5/2022 | 17/6/2026 | A flaw was found in Undertow. A potential security issue in flow control handling by the browser over http/2 may potentially cause overhead or a denial of service in the server. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.40.Final and prior to… | |
| Analizada | Media (5.3) | 0.90% | — | Redhat Jboss Enterprise Application PlatformRedhat Openstack PlatformRedhat Wildfly | 10/5/2022 | 17/6/2026 | This is a concurrency issue that can result in the wrong caller principal being returned from the session context of an EJB that is configured with a RunAs principal. In particular, the org.jboss.as.ejb3.component.EJBComponent class has an incomingRunAsIdentity field. This field is used by the… | |
| Modificada | Media (4.3) | 1.1% | — | Redhat Wildfly | 18/4/2022 | 17/6/2026 | A flaw was found in Wildfly where insufficient RBAC restrictions may lead to expose metrics data. The highest threat from this vulnerability is to the confidentiality. | |
| Modificada | Media (5.3) | 0.85% | — | Redhat Wildfly ElytronRedhat Build OF QuarkusRedhat Codeready StudioRedhat Data Grid+9 | 5/8/2021 | 17/6/2026 | A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnerability is confidentiality. | |
| Modificada | Media (5.4) | 0.57% | — | Redhat Wildfly | 7/6/2021 | 17/6/2026 | A flaw was found in wildfly. The EJBContext principle is not popped back after invoking another EJB using a different Security Domain. The highest threat from this vulnerability is to data confidentiality and integrity. Versions before wildfly 20.0.0.Final are affected. | |
| Modificada | Media (5.5) | 0.19% | — | Redhat Jboss Enterprise Application PlatformRedhat Wildfly | 2/6/2021 | 17/6/2026 | It was found that the issue for security flaw CVE-2019-3805 appeared again in a further version of JBoss Enterprise Application Platform - Continuous Delivery (EAP-CD) introducing regression. An attacker could exploit this by modifying the PID file in /var/run/jboss-eap/ allowing the init.d script to terminate any… |