RHSA-2026:0384

Advisory lineage Upstream: 3 Downstream: 0
Published: 14 Jan 2026, 10:39
Last modified:07 May 2026, 10:06

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.6 CRITICAL
3.1 (osv_red_hat)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

14 Jan 2026, 10:39
Published
Vulnerability first disclosed
07 May 2026, 10:06
Last Modified
Vulnerability information updated

Description

Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 8.1.3 security update

CVSS Metrics

  • v3.1CRITICALScore: 9.6CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L

Affected Systems

  • redhateap8-apache-cxf

    < 0:4.0.10-1.redhat_00001.1.el9eap

  • redhateap8-apache-cxf-rt

    < 0:4.0.10-1.redhat_00001.1.el9eap

  • redhateap8-apache-cxf-services

    < 0:4.0.10-1.redhat_00001.1.el9eap

  • redhateap8-apache-cxf-tools

    < 0:4.0.10-1.redhat_00001.1.el9eap

  • redhateap8-bouncycastle

    < 0:1.82.0-1.redhat_00001.1.el9eap

  • redhateap8-bouncycastle-jmail

    < 0:1.82.0-1.redhat_00001.1.el9eap

  • redhateap8-bouncycastle-pg

    < 0:1.82.0-1.redhat_00001.1.el9eap

  • redhateap8-bouncycastle-pkix

    < 0:1.82.0-1.redhat_00001.1.el9eap

  • redhateap8-bouncycastle-prov

    < 0:1.82.0-1.redhat_00001.1.el9eap

  • redhateap8-bouncycastle-util

    < 0:1.82.0-1.redhat_00001.1.el9eap

  • redhateap8-eap-product-conf-parent

    < 0:801.3.0-1.GA_redhat_00001.1.el9eap

  • redhateap8-eap-product-conf-wildfly-ee-feature-pack

    < 0:801.3.0-1.GA_redhat_00001.1.el9eap

  • redhateap8-eventstream

    < 0:1.0.1-3.redhat_00003.1.el9eap

  • redhateap8-hibernate

    < 0:6.6.36-1.Final_redhat_00001.1.el9eap

  • redhateap8-hibernate-core

    < 0:6.6.36-1.Final_redhat_00001.1.el9eap

  • redhateap8-hibernate-envers

    < 0:6.6.36-1.Final_redhat_00001.1.el9eap

  • redhateap8-jboss-el-api_5.0_spec

    < 0:4.0.2-1.Final_redhat_00001.1.el9eap

  • redhateap8-jboss-threads

    < 0:2.5.0-1.redhat_00001.1.el9eap

  • redhateap8-undertow

    < 0:2.3.20-2.SP4_redhat_00001.1.el9eap

  • redhateap8-wildfly

    < 0:8.1.3-4.GA_redhat_00006.1.el9eap

  • redhateap8-wildfly-clustering

    < 0:5.0.12-1.Final_redhat_00001.1.el9eap

  • redhateap8-wildfly-clustering-cache-infinispan-common

    < 0:5.0.12-1.Final_redhat_00001.1.el9eap

  • redhateap8-wildfly-clustering-cache-infinispan-embedded

    < 0:5.0.12-1.Final_redhat_00001.1.el9eap

  • redhateap8-wildfly-clustering-cache-infinispan-remote

    < 0:5.0.12-1.Final_redhat_00001.1.el9eap

  • redhateap8-wildfly-clustering-cache-spi

    < 0:5.0.12-1.Final_redhat_00001.1.el9eap

  • redhateap8-wildfly-clustering-context

    < 0:5.0.12-1.Final_redhat_00001.1.el9eap

  • redhateap8-wildfly-clustering-marshalling-jboss

    < 0:5.0.12-1.Final_redhat_00001.1.el9eap

  • redhateap8-wildfly-clustering-marshalling-protostream

    < 0:5.0.12-1.Final_redhat_00001.1.el9eap

  • redhateap8-wildfly-clustering-marshalling-spi

    < 0:5.0.12-1.Final_redhat_00001.1.el9eap

  • redhateap8-wildfly-clustering-server-api

    < 0:5.0.12-1.Final_redhat_00001.1.el9eap

  • redhateap8-wildfly-clustering-server-infinispan

    < 0:5.0.12-1.Final_redhat_00001.1.el9eap

  • redhateap8-wildfly-clustering-server-jgroups

    < 0:5.0.12-1.Final_redhat_00001.1.el9eap

  • redhateap8-wildfly-clustering-server-local

    < 0:5.0.12-1.Final_redhat_00001.1.el9eap

  • redhateap8-wildfly-clustering-server-spi

    < 0:5.0.12-1.Final_redhat_00001.1.el9eap

  • redhateap8-wildfly-clustering-session-cache

    < 0:5.0.12-1.Final_redhat_00001.1.el9eap

  • redhateap8-wildfly-clustering-session-infinispan-embedded

    < 0:5.0.12-1.Final_redhat_00001.1.el9eap

  • redhateap8-wildfly-clustering-session-infinispan-remote

    < 0:5.0.12-1.Final_redhat_00001.1.el9eap

  • redhateap8-wildfly-clustering-session-spec-servlet-6.0

    < 0:5.0.12-1.Final_redhat_00001.1.el9eap

  • redhateap8-wildfly-clustering-session-spec-spi

    < 0:5.0.12-1.Final_redhat_00001.1.el9eap

  • redhateap8-wildfly-clustering-session-spi

    < 0:5.0.12-1.Final_redhat_00001.1.el9eap

  • redhateap8-wildfly-elytron

    < 0:2.6.6-1.Final_redhat_00001.1.el9eap

  • redhateap8-wildfly-elytron-tool

    < 0:2.6.6-1.Final_redhat_00001.1.el9eap

  • redhateap8-wildfly-java-jdk17

    < 0:8.1.3-4.GA_redhat_00006.1.el9eap

  • redhateap8-wildfly-java-jdk21

    < 0:8.1.3-4.GA_redhat_00006.1.el9eap

  • redhateap8-wildfly-javadocs

    < 0:8.1.1-4.GA_redhat_00007.1.el9eap

  • redhateap8-wildfly-modules

    < 0:8.1.3-4.GA_redhat_00006.1.el9eap

References (38)