1. Home
  2. Blog
  3. Wildfly

Wildfly

4 posts tagged with “Wildfly”

CVE-2026-15554: Undertow AJP Authentication Bypass via Forged Client Certificate Attributes
cvesecurityvulnerability

CVE-2026-15554: Undertow AJP Authentication Bypass via Forged Client Certificate Attributes

Undertow AJP CLIENT-CERT authentication bypass via forged ssl_cert and is_ssl attributes. An unauthenticated attacker who reaches port 8009 can bypass mutual TLS authentication. Part of the Ghostcat-class AJP trust model flaws.

Aug 11, 2026
Read
CVE-2026-15555: JBoss EAP Deserialization RCE via Unfiltered River Unmarshaller in Session Replication
cvesecurityvulnerability

CVE-2026-15555: JBoss EAP Deserialization RCE via Unfiltered River Unmarshaller in Session Replication

JBoss EAP and WildFly cluster deserialization RCE. The Infinispan session replication path deserializes through JBoss Marshalling River unmarshaller with no class filtering. Network access to the clustering port yields code execution on every cluster node.

Aug 11, 2026
Read
CVE-2026-24329: WildFly Denial of Service via Malformed Payload Injection
cvesecurityvulnerability

CVE-2026-24329: WildFly Denial of Service via Malformed Payload Injection

WildFly-core Management Model writes unsanitized user input into standalone.xml, allowing an admin to corrupt the config file and cause an unrecoverable server crash.

Aug 11, 2026
Read
CVE-2026-24330: WildFly Arbitrary File Read via Malicious Archive Deployment
cvesecurityvulnerability

CVE-2026-24330: WildFly Arbitrary File Read via Malicious Archive Deployment

WildFly-core deployment handler accepts malicious archives from authenticated deployer-role users, enabling arbitrary file read of server filesystem including credentials and configuration secrets.

Aug 11, 2026
Read
  1. Home
  2. Blog
  3. Wildfly

Wildfly

4 posts tagged with “Wildfly”

CVE-2026-15554: Undertow AJP Authentication Bypass via Forged Client Certificate Attributes
cvesecurityvulnerability

CVE-2026-15554: Undertow AJP Authentication Bypass via Forged Client Certificate Attributes

Undertow AJP CLIENT-CERT authentication bypass via forged ssl_cert and is_ssl attributes. An unauthenticated attacker who reaches port 8009 can bypass mutual TLS authentication. Part of the Ghostcat-class AJP trust model flaws.

Aug 11, 2026
Read
CVE-2026-15555: JBoss EAP Deserialization RCE via Unfiltered River Unmarshaller in Session Replication
cvesecurityvulnerability

CVE-2026-15555: JBoss EAP Deserialization RCE via Unfiltered River Unmarshaller in Session Replication

JBoss EAP and WildFly cluster deserialization RCE. The Infinispan session replication path deserializes through JBoss Marshalling River unmarshaller with no class filtering. Network access to the clustering port yields code execution on every cluster node.

Aug 11, 2026
Read
CVE-2026-24329: WildFly Denial of Service via Malformed Payload Injection
cvesecurityvulnerability

CVE-2026-24329: WildFly Denial of Service via Malformed Payload Injection

WildFly-core Management Model writes unsanitized user input into standalone.xml, allowing an admin to corrupt the config file and cause an unrecoverable server crash.

Aug 11, 2026
Read
CVE-2026-24330: WildFly Arbitrary File Read via Malicious Archive Deployment
cvesecurityvulnerability

CVE-2026-24330: WildFly Arbitrary File Read via Malicious Archive Deployment

WildFly-core deployment handler accepts malicious archives from authenticated deployer-role users, enabling arbitrary file read of server filesystem including credentials and configuration secrets.

Aug 11, 2026
Read
HOL LogoHOL
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.