Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
RHSA-2026:3891
See a problem?
Please try reporting it
to the source
first.
Source
https://access.redhat.com/errata/RHSA-2026:3891
Import Source
https://security.access.redhat.com/data/osv/RHSA-2026:3891.json
JSON Data
https://api.osv.dev/v1/vulns/RHSA-2026:3891
Upstream
CVE-2024-3884
CVE-2025-12543
CVE-2025-9784
Published
2026-03-06T10:13:29Z
Modified
2026-03-06T10:46:08.980676Z
Severity
9.6 (Critical)
CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L
CVSS Calculator
Summary
Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 8.0.12 security update
Details
References
https://access.redhat.com/errata/RHSA-2026:3891
https://access.redhat.com/security/updates/classification/#important
https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/8.0
https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/8.0/html/release_notes_for_red_hat_jboss_enterprise_application_platform_8.0/index
https://access.redhat.com/articles/7120566
https://bugzilla.redhat.com/show_bug.cgi?id=2275287
https://bugzilla.redhat.com/show_bug.cgi?id=2392306
https://bugzilla.redhat.com/show_bug.cgi?id=2408784
https://issues.redhat.com/browse/JBEAP-31073
https://issues.redhat.com/browse/JBEAP-31251
https://issues.redhat.com/browse/JBEAP-31325
https://issues.redhat.com/browse/JBEAP-31343
https://issues.redhat.com/browse/JBEAP-31358
https://issues.redhat.com/browse/JBEAP-31397
https://issues.redhat.com/browse/JBEAP-31420
https://issues.redhat.com/browse/JBEAP-31438
https://issues.redhat.com/browse/JBEAP-31446
https://issues.redhat.com/browse/JBEAP-31453
https://issues.redhat.com/browse/JBEAP-31566
https://issues.redhat.com/browse/JBEAP-31579
https://issues.redhat.com/browse/JBEAP-31596
https://issues.redhat.com/browse/JBEAP-31679
https://issues.redhat.com/browse/JBEAP-31708
https://issues.redhat.com/browse/JBEAP-31712
https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_3891.json
https://access.redhat.com/security/cve/CVE-2024-3884
https://www.cve.org/CVERecord?id=CVE-2024-3884
https://nvd.nist.gov/vuln/detail/CVE-2024-3884
https://access.redhat.com/security/cve/CVE-2025-9784
https://www.cve.org/CVERecord?id=CVE-2025-9784
https://nvd.nist.gov/vuln/detail/CVE-2025-9784
https://github.com/undertow-io/undertow/pull/1778
https://github.com/undertow-io/undertow/releases/tag/2.2.38.Final
https://issues.redhat.com/browse/UNDERTOW-2598
https://kb.cert.org/vuls/id/767506
https://access.redhat.com/security/cve/CVE-2025-12543
https://www.cve.org/CVERecord?id=CVE-2025-12543
https://nvd.nist.gov/vuln/detail/CVE-2025-12543
Affected packages
Red Hat:jboss_enterprise_application_platform:8.0::el9
eap8-bouncycastle
Package
Name
eap8-bouncycastle
Purl
pkg:rpm/redhat/eap8-bouncycastle
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.83.0-1.redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3891.json"
eap8-bouncycastle-jmail
Package
Name
eap8-bouncycastle-jmail
Purl
pkg:rpm/redhat/eap8-bouncycastle-jmail
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.83.0-1.redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3891.json"
eap8-bouncycastle-pg
Package
Name
eap8-bouncycastle-pg
Purl
pkg:rpm/redhat/eap8-bouncycastle-pg
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.83.0-1.redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3891.json"
eap8-bouncycastle-pkix
Package
Name
eap8-bouncycastle-pkix
Purl
pkg:rpm/redhat/eap8-bouncycastle-pkix
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.83.0-1.redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3891.json"
eap8-bouncycastle-prov
Package
Name
eap8-bouncycastle-prov
Purl
pkg:rpm/redhat/eap8-bouncycastle-prov
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.83.0-1.redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3891.json"
eap8-bouncycastle-util
Package
Name
eap8-bouncycastle-util
Purl
pkg:rpm/redhat/eap8-bouncycastle-util
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.83.0-1.redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3891.json"
eap8-codemodel
Package
Name
eap8-codemodel
Purl
pkg:rpm/redhat/eap8-codemodel
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.0.6-1.redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3891.json"
eap8-guava
Package
Name
eap8-guava
Purl
pkg:rpm/redhat/eap8-guava
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:33.0.0-2.jre_redhat_00003.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3891.json"
eap8-guava-libraries
Package
Name
eap8-guava-libraries
Purl
pkg:rpm/redhat/eap8-guava-libraries
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:33.0.0-2.jre_redhat_00003.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3891.json"
eap8-jaxb
Package
Name
eap8-jaxb
Purl
pkg:rpm/redhat/eap8-jaxb
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.0.6-1.redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3891.json"
eap8-jaxb-core
Package
Name
eap8-jaxb-core
Purl
pkg:rpm/redhat/eap8-jaxb-core
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.0.6-1.redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3891.json"
eap8-jaxb-jxc
Package
Name
eap8-jaxb-jxc
Purl
pkg:rpm/redhat/eap8-jaxb-jxc
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.0.6-1.redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3891.json"
eap8-jaxb-runtime
Package
Name
eap8-jaxb-runtime
Purl
pkg:rpm/redhat/eap8-jaxb-runtime
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.0.6-1.redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3891.json"
eap8-jaxb-xjc
Package
Name
eap8-jaxb-xjc
Purl
pkg:rpm/redhat/eap8-jaxb-xjc
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.0.6-1.redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3891.json"
eap8-jcip-annotations
Package
Name
eap8-jcip-annotations
Purl
pkg:rpm/redhat/eap8-jcip-annotations
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.0.0-3.redhat_00009.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3891.json"
eap8-relaxng-datatype
Package
Name
eap8-relaxng-datatype
Purl
pkg:rpm/redhat/eap8-relaxng-datatype
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.0.6-1.redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3891.json"
eap8-rngom
Package
Name
eap8-rngom
Purl
pkg:rpm/redhat/eap8-rngom
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.0.6-1.redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3891.json"
eap8-slf4j-jboss-logmanager
Package
Name
eap8-slf4j-jboss-logmanager
Purl
pkg:rpm/redhat/eap8-slf4j-jboss-logmanager
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.0.2-1.Final_redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3891.json"
eap8-txw2
Package
Name
eap8-txw2
Purl
pkg:rpm/redhat/eap8-txw2
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.0.6-1.redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3891.json"
eap8-undertow
Package
Name
eap8-undertow
Purl
pkg:rpm/redhat/eap8-undertow
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.3.23-1.SP3_redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3891.json"
eap8-xsom
Package
Name
eap8-xsom
Purl
pkg:rpm/redhat/eap8-xsom
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:4.0.6-1.redhat_00001.1.el9eap
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:3891.json"
RHSA-2026:3891 - OSV