CODERED VTA

Red Hat Patches Seven JBoss EAP Flaws Including Netty Request Smuggling and JNDI Code Execution

High
Data centre racks with yellow cabling
Photo by D Coetzee on Flickr

Red Hat published errata RHSA-2026:73976 on 30 September 2026, delivering Red Hat JBoss Enterprise Application Platform 7.1.16 as a replacement for 7.1.15 and closing seven separate vulnerabilities. The update applies to JBoss EAP 7.1 EUS running on Red Hat Enterprise Linux 7 on x86_64, and Red Hat Product Security has rated the overall security impact as Important. The fixed flaws sit in three bundled third-party libraries rather than in WildFly itself: mchange-commons-java (CVE-2026-27727), the c3p0 connection pool (CVE-2026-27830), and five issues in Netty (CVE-2026-42578, CVE-2026-42581, CVE-2026-42583, CVE-2026-42584 and CVE-2026-42585). Any organisation still running the 7.1 extended update support stream of EAP on RHEL 7 is in scope, which typically means long-lived Java application estates that have been held back on an older platform branch for compatibility reasons. The release also carries an Undertow upgrade from 1.4.18.SP19 to 1.4.18.SP20 alongside the security fixes.

Red Hat's advisory describes each defect at a summary level and does not publish exploitation details, proof-of-concept code, or attack telemetry, so the mechanism below is limited to what the vendor states. CVE-2026-27727 in mchange-commons-java allows arbitrary code execution through JNDI dereferencing of crafted objects, the same class of lookup abuse that has repeatedly plagued Java middleware. CVE-2026-27830 in c3p0 allows arbitrary code execution through deserialization of crafted objects, meaning an attacker who can get untrusted serialized data into a deserialization path may be able to run code in the context of the application server. The Netty issues split into a denial-of-service problem and a cluster of HTTP parsing defects: CVE-2026-42583 permits excessive memory allocation in the LZ4FrameDecoder, CVE-2026-42578 allows HTTP header injection because validation is disabled in HttpProxyHandler, CVE-2026-42581 enables request smuggling through improper handling of conflicting HTTP/1.0 headers, CVE-2026-42585 enables smuggling via malformed Transfer-Encoding parsing, and CVE-2026-42584 causes data confusion through incorrect HTTP response parsing. Red Hat notes that a CVSS base score for each individual issue is available from the linked CVE pages rather than in the errata text itself.

The strategic concern is where these components sit. JBoss EAP commonly fronts business applications in banking, government and telecommunications environments, often behind a reverse proxy or load balancer, and that is precisely the topology where HTTP request smuggling is most damaging: a front-end and a back-end that disagree on message boundaries can allow an attacker to slip a second request past perimeter filtering, poison a shared connection, or reach endpoints the proxy believes it is protecting. The two code-execution flaws are more serious in principle, since JNDI dereferencing and Java deserialization bugs have historically been the fastest route from an exposed application endpoint to server-side code execution, though both depend on an application path that actually feeds attacker-influenced data into the vulnerable library. The LZ4 decompression flaw is a resource-exhaustion risk against availability rather than a route to compromise. On current exploitation status, the only authoritative data available comes from FIRST EPSS, which places all seven issues at low near-term likelihood: CVE-2026-27830 at 2.1 percent probability of exploitation in the next 30 days, CVE-2026-27727 at 1.6 percent, CVE-2026-42578 at 1.2 percent, CVE-2026-42581 and CVE-2026-42584 at 0.7 percent, CVE-2026-42583 at 0.5 percent and CVE-2026-42585 at 0.3 percent. No active campaign, in-the-wild exploitation or public exploit is described in the advisory. The practical exposure is therefore the ordinary one for an EUS platform: estates that defer middleware patching for change-control reasons will carry seven known library defects, two of them code-execution class, on internet-facing or partner-facing Java services until the release is rolled out.

Attack Surface

Web Application, Server OS, Supply Chain (Third-party vendors)

Tactics

Initial Access, Execution, Impact

Techniques

  • T1190 – Exploit Public-Facing Application
  • T1059 – Command and Scripting Interpreter
  • T1499 – Endpoint Denial of Service
  • T1499.004 – Application or System Exploitation

SuperPRO's Threat Countermeasures Procedures

  1. Apply RHSA-2026:73976 to upgrade Red Hat JBoss EAP 7.1 EUS on RHEL 7 x86_64 from 7.1.15 to 7.1.16, installing eap7-wildfly-7.1.16-1.GA_redhat_00002.1.ep7.el7, eap7-wildfly-modules-7.1.16-1.GA_redhat_00002.1.ep7.el7, eap7-netty-4.1.63-4.Final_redhat_00005.1.ep7.el7 and eap7-hibernate-5.1.17-5.Final_redhat_00006.1.ep7.el7, then restart the EAP service so the new modules are loaded.
  2. Verify package integrity before deployment against the SHA-256 digests published in the errata, for example 84ba05b9b3c02c77ec515c9861caf795a191873ca3ff8e168c34fe48e8ab2c35 for eap7-wildfly-7.1.16 noarch and 6c29e07901e03578157de0240e04b3bfd0019a4cd68b7b868f23980906cf5291 for eap7-netty-4.1.63 noarch, and confirm the Undertow module has moved from 1.4.18.SP19 to 1.4.18.SP20 per JBEAP-33911.
  3. Follow the prerequisites in Red Hat article 11258 before patching: apply any previously released errata for the system and take a full backup of the EAP installation including deployed applications, configuration files and database settings, since 7.1 EUS nodes are frequently long-running production instances.
  4. Inventory deployments for the vulnerable libraries independently of the EAP version string by searching module directories for mchange-commons-java and c3p0 JARs (CVE-2026-27727 and CVE-2026-27830) and for netty-codec, netty-codec-http and netty-handler-proxy JARs below 4.1.63.Final-redhat-00005, since applications may ship their own copies inside WAR or EAR files that the RPM update does not replace.
  5. Where c3p0 is used for connection pooling, restrict JNDI lookups to the local context and block outbound LDAP and RMI egress from EAP hosts on TCP/389, TCP/636 and TCP/1099 at the perimeter firewall, which removes the remote fetch step the CVE-2026-27727 JNDI dereferencing flaw depends on.
  6. Enable strict HTTP message validation on any reverse proxy or load balancer fronting EAP and reject requests that carry both Content-Length and Transfer-Encoding headers, duplicate Content-Length values, or malformed Transfer-Encoding chunk encodings, directly countering the smuggling conditions in CVE-2026-42581 and CVE-2026-42585.
  7. Alert in application and JVM monitoring on sudden heap growth or OutOfMemoryError events in Netty pipelines using LZ4FrameDecoder (CVE-2026-42583), and log and review any HTTP response parsed by EAP that produces mismatched request and response pairing, which is the observable symptom of the CVE-2026-42584 data confusion issue.

Source

Code Red Cyber / VTA – coderedcyber.ai