CVE-2026-5680: Red Hat Build Of Apache Camel - Hawtio 4
High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.
A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead to excessive memory consumption due to the PerMessageDeflateFunction.largerBuffer() method using exponential doubling, resulting in a Denial of Service (DoS) for the affected application.
Affected products
- Red Hat Red Hat Build Of Apache Camel - Hawtio 4
- Red Hat Red Hat Build Of Apache Camel For Spring Boot 4
- Red Hat Red Hat Data Grid 8
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 9
- Red Hat Red Hat Fuse 7
- Red Hat Red Hat JBoss Enterprise Application Platform 7
- Red Hat Red Hat JBoss Enterprise Application Platform 8.1 For Rhel 10: before 0:2.40.0-8.redhat_00024.1.el10eap (fixed in 0:2.40.0-8.redhat_00024.1.el10eap); before 0:4.1.7-1.SP1_redhat_00001.1.el10eap (fixed in 0:4.1.7-1.SP1_redhat_00001.1.el10eap); before 0:2.0.5-1.Final_redhat_00001.1.el10eap (fixed in 0:2.0.5-1.Final_redhat_00001.1.el10eap); before 0:1.85.0-1.redhat_00001.1.el10eap (fixed in 0:1.85.0-1.redhat_00001.1.el10eap); before 0:1.2.7-1.redhat_00002.1.el10eap (fixed in 0:1.2.7-1.redhat_00002.1.el10eap); before 0:801.8.0-1.GA_redhat_00001.1.el10eap (fixed in 0:801.8.0-1.GA_redhat_00001.1.el10eap); …
- Red Hat Red Hat JBoss Enterprise Application Platform 8.1 For Rhel 8: before 0:2.40.0-8.redhat_00024.1.el8eap (fixed in 0:2.40.0-8.redhat_00024.1.el8eap); before 0:4.1.7-1.SP1_redhat_00001.1.el8eap (fixed in 0:4.1.7-1.SP1_redhat_00001.1.el8eap); before 0:2.0.5-1.Final_redhat_00001.1.el8eap (fixed in 0:2.0.5-1.Final_redhat_00001.1.el8eap); before 0:1.85.0-1.redhat_00001.1.el8eap (fixed in 0:1.85.0-1.redhat_00001.1.el8eap); before 0:1.2.7-1.redhat_00002.1.el8eap (fixed in 0:1.2.7-1.redhat_00002.1.el8eap); before 0:801.8.0-1.GA_redhat_00001.1.el8eap (fixed in 0:801.8.0-1.GA_redhat_00001.1.el8eap); …
- Red Hat Red Hat JBoss Enterprise Application Platform 8.1 For Rhel 9: before 0:2.40.0-8.redhat_00024.1.el9eap (fixed in 0:2.40.0-8.redhat_00024.1.el9eap); before 0:4.1.7-1.SP1_redhat_00001.1.el9eap (fixed in 0:4.1.7-1.SP1_redhat_00001.1.el9eap); before 0:2.0.5-1.Final_redhat_00001.1.el9eap (fixed in 0:2.0.5-1.Final_redhat_00001.1.el9eap); before 0:1.85.0-1.redhat_00001.1.el9eap (fixed in 0:1.85.0-1.redhat_00001.1.el9eap); before 0:1.2.7-1.redhat_00002.1.el9eap (fixed in 0:1.2.7-1.redhat_00002.1.el9eap); before 0:801.8.0-1.GA_redhat_00001.1.el9eap (fixed in 0:801.8.0-1.GA_redhat_00001.1.el9eap); …
- Red Hat Red Hat JBoss Enterprise Application Platform Expansion Pack
- Red Hat Red Hat Process Automation 7
- Red Hat Red Hat Single Sign-On 7
Published 2026-08-27. Last modified 2026-09-22.