Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
RHSA-2026:0384
See a problem?
Please try reporting it
to the source
first.
Source
https://access.redhat.com/errata/RHSA-2026:0384
Import Source
https://security.access.redhat.com/data/osv/RHSA-2026:0384.json
JSON Data
https://api.osv.dev/v1/vulns/RHSA-2026:0384
Upstream
CVE-2024-3884
CVE-2025-12543
CVE-2025-9784
Published
2026-01-14T10:39:01Z
Modified
2026-01-21T10:25:22.510836Z
Severity
9.6 (Critical)
CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L
CVSS Calculator
Summary
Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 8.1.3 security update
Details
References
https://access.redhat.com/errata/RHSA-2026:0384
https://issues.redhat.com/browse/JBEAP-31345
https://issues.redhat.com/browse/JBEAP-31374
https://issues.redhat.com/browse/JBEAP-31380
https://issues.redhat.com/browse/JBEAP-31396
https://issues.redhat.com/browse/JBEAP-31414
https://issues.redhat.com/browse/JBEAP-31421
https://issues.redhat.com/browse/JBEAP-31474
https://issues.redhat.com/browse/JBEAP-31494
https://issues.redhat.com/browse/JBEAP-31495
https://issues.redhat.com/browse/JBEAP-31601
https://issues.redhat.com/browse/JBEAP-31250
https://issues.redhat.com/browse/JBEAP-31326
https://access.redhat.com/security/updates/classification/#important
https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/8.1
https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/8.1/html/release_notes_for_red_hat_jboss_enterprise_application_platform_8.1/index
https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/8.1/html/red_hat_jboss_enterprise_application_platform_installation_methods/index
https://access.redhat.com/articles/7134190
https://bugzilla.redhat.com/show_bug.cgi?id=2275287
https://bugzilla.redhat.com/show_bug.cgi?id=2392306
https://bugzilla.redhat.com/show_bug.cgi?id=2408784
https://issues.redhat.com/browse/JBEAP-31344
https://issues.redhat.com/browse/JBEAP-30596
https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_0384.json
https://access.redhat.com/security/cve/CVE-2024-3884
https://www.cve.org/CVERecord?id=CVE-2024-3884
https://nvd.nist.gov/vuln/detail/CVE-2024-3884
https://access.redhat.com/security/cve/CVE-2025-9784
https://www.cve.org/CVERecord?id=CVE-2025-9784
https://nvd.nist.gov/vuln/detail/CVE-2025-9784
https://github.com/undertow-io/undertow/pull/1778
https://github.com/undertow-io/undertow/releases/tag/2.2.38.Final
https://issues.redhat.com/browse/UNDERTOW-2598
https://kb.cert.org/vuls/id/767506
https://access.redhat.com/security/cve/CVE-2025-12543
https://www.cve.org/CVERecord?id=CVE-2025-12543
https://nvd.nist.gov/vuln/detail/CVE-2025-12543
Affected packages
Red Hat:jboss_enterprise_application_platform:8.1::el9
eap8-apache-cxf
Package
Name
eap8-apache-cxf
Purl
pkg:rpm/redhat/eap8-apache-cxf
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.0.10-1.redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-apache-cxf-rt
Package
Name
eap8-apache-cxf-rt
Purl
pkg:rpm/redhat/eap8-apache-cxf-rt
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.0.10-1.redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-apache-cxf-services
Package
Name
eap8-apache-cxf-services
Purl
pkg:rpm/redhat/eap8-apache-cxf-services
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.0.10-1.redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-apache-cxf-tools
Package
Name
eap8-apache-cxf-tools
Purl
pkg:rpm/redhat/eap8-apache-cxf-tools
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.0.10-1.redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-bouncycastle
Package
Name
eap8-bouncycastle
Purl
pkg:rpm/redhat/eap8-bouncycastle
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.82.0-1.redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-bouncycastle-jmail
Package
Name
eap8-bouncycastle-jmail
Purl
pkg:rpm/redhat/eap8-bouncycastle-jmail
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.82.0-1.redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-bouncycastle-pg
Package
Name
eap8-bouncycastle-pg
Purl
pkg:rpm/redhat/eap8-bouncycastle-pg
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.82.0-1.redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-bouncycastle-pkix
Package
Name
eap8-bouncycastle-pkix
Purl
pkg:rpm/redhat/eap8-bouncycastle-pkix
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.82.0-1.redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-bouncycastle-prov
Package
Name
eap8-bouncycastle-prov
Purl
pkg:rpm/redhat/eap8-bouncycastle-prov
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.82.0-1.redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-bouncycastle-util
Package
Name
eap8-bouncycastle-util
Purl
pkg:rpm/redhat/eap8-bouncycastle-util
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.82.0-1.redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-eap-product-conf-parent
Package
Name
eap8-eap-product-conf-parent
Purl
pkg:rpm/redhat/eap8-eap-product-conf-parent
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:801.3.0-1.GA_redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-eap-product-conf-wildfly-ee-feature-pack
Package
Name
eap8-eap-product-conf-wildfly-ee-feature-pack
Purl
pkg:rpm/redhat/eap8-eap-product-conf-wildfly-ee-feature-pack
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:801.3.0-1.GA_redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-eventstream
Package
Name
eap8-eventstream
Purl
pkg:rpm/redhat/eap8-eventstream
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.0.1-3.redhat_00003.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-hibernate
Package
Name
eap8-hibernate
Purl
pkg:rpm/redhat/eap8-hibernate
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:6.6.36-1.Final_redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-hibernate-core
Package
Name
eap8-hibernate-core
Purl
pkg:rpm/redhat/eap8-hibernate-core
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:6.6.36-1.Final_redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-hibernate-envers
Package
Name
eap8-hibernate-envers
Purl
pkg:rpm/redhat/eap8-hibernate-envers
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:6.6.36-1.Final_redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-jboss-el-api_5.0_spec
Package
Name
eap8-jboss-el-api_5.0_spec
Purl
pkg:rpm/redhat/eap8-jboss-el-api_5.0_spec
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.0.2-1.Final_redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-jboss-threads
Package
Name
eap8-jboss-threads
Purl
pkg:rpm/redhat/eap8-jboss-threads
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.5.0-1.redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-undertow
Package
Name
eap8-undertow
Purl
pkg:rpm/redhat/eap8-undertow
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.3.20-2.SP4_redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-wildfly
Package
Name
eap8-wildfly
Purl
pkg:rpm/redhat/eap8-wildfly
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:8.1.3-4.GA_redhat_00006.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-wildfly-clustering
Package
Name
eap8-wildfly-clustering
Purl
pkg:rpm/redhat/eap8-wildfly-clustering
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:5.0.12-1.Final_redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-wildfly-clustering-cache-infinispan-common
Package
Name
eap8-wildfly-clustering-cache-infinispan-common
Purl
pkg:rpm/redhat/eap8-wildfly-clustering-cache-infinispan-common
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:5.0.12-1.Final_redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-wildfly-clustering-cache-infinispan-embedded
Package
Name
eap8-wildfly-clustering-cache-infinispan-embedded
Purl
pkg:rpm/redhat/eap8-wildfly-clustering-cache-infinispan-embedded
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:5.0.12-1.Final_redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-wildfly-clustering-cache-infinispan-remote
Package
Name
eap8-wildfly-clustering-cache-infinispan-remote
Purl
pkg:rpm/redhat/eap8-wildfly-clustering-cache-infinispan-remote
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:5.0.12-1.Final_redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-wildfly-clustering-cache-spi
Package
Name
eap8-wildfly-clustering-cache-spi
Purl
pkg:rpm/redhat/eap8-wildfly-clustering-cache-spi
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:5.0.12-1.Final_redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-wildfly-clustering-context
Package
Name
eap8-wildfly-clustering-context
Purl
pkg:rpm/redhat/eap8-wildfly-clustering-context
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:5.0.12-1.Final_redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-wildfly-clustering-marshalling-jboss
Package
Name
eap8-wildfly-clustering-marshalling-jboss
Purl
pkg:rpm/redhat/eap8-wildfly-clustering-marshalling-jboss
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:5.0.12-1.Final_redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-wildfly-clustering-marshalling-protostream
Package
Name
eap8-wildfly-clustering-marshalling-protostream
Purl
pkg:rpm/redhat/eap8-wildfly-clustering-marshalling-protostream
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:5.0.12-1.Final_redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-wildfly-clustering-marshalling-spi
Package
Name
eap8-wildfly-clustering-marshalling-spi
Purl
pkg:rpm/redhat/eap8-wildfly-clustering-marshalling-spi
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:5.0.12-1.Final_redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-wildfly-clustering-server-api
Package
Name
eap8-wildfly-clustering-server-api
Purl
pkg:rpm/redhat/eap8-wildfly-clustering-server-api
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:5.0.12-1.Final_redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-wildfly-clustering-server-infinispan
Package
Name
eap8-wildfly-clustering-server-infinispan
Purl
pkg:rpm/redhat/eap8-wildfly-clustering-server-infinispan
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:5.0.12-1.Final_redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-wildfly-clustering-server-jgroups
Package
Name
eap8-wildfly-clustering-server-jgroups
Purl
pkg:rpm/redhat/eap8-wildfly-clustering-server-jgroups
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:5.0.12-1.Final_redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-wildfly-clustering-server-local
Package
Name
eap8-wildfly-clustering-server-local
Purl
pkg:rpm/redhat/eap8-wildfly-clustering-server-local
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:5.0.12-1.Final_redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-wildfly-clustering-server-spi
Package
Name
eap8-wildfly-clustering-server-spi
Purl
pkg:rpm/redhat/eap8-wildfly-clustering-server-spi
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:5.0.12-1.Final_redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-wildfly-clustering-session-cache
Package
Name
eap8-wildfly-clustering-session-cache
Purl
pkg:rpm/redhat/eap8-wildfly-clustering-session-cache
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:5.0.12-1.Final_redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-wildfly-clustering-session-infinispan-embedded
Package
Name
eap8-wildfly-clustering-session-infinispan-embedded
Purl
pkg:rpm/redhat/eap8-wildfly-clustering-session-infinispan-embedded
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:5.0.12-1.Final_redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-wildfly-clustering-session-infinispan-remote
Package
Name
eap8-wildfly-clustering-session-infinispan-remote
Purl
pkg:rpm/redhat/eap8-wildfly-clustering-session-infinispan-remote
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:5.0.12-1.Final_redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-wildfly-clustering-session-spec-servlet-6.0
Package
Name
eap8-wildfly-clustering-session-spec-servlet-6.0
Purl
pkg:rpm/redhat/eap8-wildfly-clustering-session-spec-servlet-6.0
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:5.0.12-1.Final_redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-wildfly-clustering-session-spec-spi
Package
Name
eap8-wildfly-clustering-session-spec-spi
Purl
pkg:rpm/redhat/eap8-wildfly-clustering-session-spec-spi
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:5.0.12-1.Final_redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-wildfly-clustering-session-spi
Package
Name
eap8-wildfly-clustering-session-spi
Purl
pkg:rpm/redhat/eap8-wildfly-clustering-session-spi
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:5.0.12-1.Final_redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-wildfly-elytron
Package
Name
eap8-wildfly-elytron
Purl
pkg:rpm/redhat/eap8-wildfly-elytron
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.6.6-1.Final_redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-wildfly-elytron-tool
Package
Name
eap8-wildfly-elytron-tool
Purl
pkg:rpm/redhat/eap8-wildfly-elytron-tool
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.6.6-1.Final_redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-wildfly-java-jdk17
Package
Name
eap8-wildfly-java-jdk17
Purl
pkg:rpm/redhat/eap8-wildfly-java-jdk17
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:8.1.3-4.GA_redhat_00006.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-wildfly-java-jdk21
Package
Name
eap8-wildfly-java-jdk21
Purl
pkg:rpm/redhat/eap8-wildfly-java-jdk21
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:8.1.3-4.GA_redhat_00006.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-wildfly-javadocs
Package
Name
eap8-wildfly-javadocs
Purl
pkg:rpm/redhat/eap8-wildfly-javadocs
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:8.1.1-4.GA_redhat_00007.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
eap8-wildfly-modules
Package
Name
eap8-wildfly-modules
Purl
pkg:rpm/redhat/eap8-wildfly-modules
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:8.1.3-4.GA_redhat_00006.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0384.json"
RHSA-2026:0384 - OSV