CVE-2026-15565

🟡 Monitoruj

Błąd w Undertow umożliwia zdalnemu atakującemu wywołanie braku pamięci na końcówce WebSocket, co prowadzi do ataku typu Denial of Service.

CVSS
7.5
EPSS
0.5%
Exploit
none
Vendor
Opis źródłowy (NVD)

A flaw was found in Undertow. A remote attacker can cause Out of Memory on websockets endpoint without authentication on any @ServerEndpoint class that has any @OnMessage method. This allows an attacker to cause Denial of Service attack without authentication and using only a standard WebSocket handshake.

dos Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.5%
Opublikowano (NVD)2026-08-11 09:17:13 UTC
Ostatnia modyfikacja (NVD)2026-09-18 00:16:56 UTC
Referencje