Red Hat JBoss Enterprise Application Platform
Red Hat JBoss Enterprise Application Platform (JBoss EAP) delivers enterprise-grade security, performance, and scalability in any environment. Red Hat supports deploying JBoss EAP on-premise, on hyperscalers, and on OpenShift. Whether on-premise, virtual, or in private, public, or hybrid clouds, JBoss EAP can help you deliver apps faster, everywhere. Customers of the Red Hat Ansible Automation Platform can take advantage of the Red Hat Ansible Certified Content Collections for Runtimes to automate the deployment of various runtimes products and components, including JBoss EAP 7.4.
Browse the latest documentation
Latest security advisories
| Severity | Advisory/CVE | Synopsis | Date |
|---|---|---|---|
| Severity Moderate | Advisory/CVECVE-2026-66276 | Synopsis A flaw was found in Apache Qpid Proton-J. An authenticated attacker can exploit this vulnerability by crafting a specially designed disposition frame with large or illegal ranges. This can cause excessive CPU usage due to naive range handling, leading to a denial of service (DoS) for the affected system. | Date |
| Severity Moderate | Advisory/CVECVE-2026-66275 | Synopsis A flaw was found in Apache Qpid Proton-J. An authenticated attacker could exploit this by exceeding the session flow control incoming window. This action could lead to a denial of service (DoS), making the system unavailable to legitimate users. | Date |
| Severity Important | Advisory/CVE(RHSA-2026:50085) Important: Red Hat JBoss Enterprise Application Platform 8.1.7.1 XP 6.0.5.1 release | Synopsis Important: Red Hat JBoss Enterprise Application Platform 8.1.7.1 XP 6.0.5.1 release | Date |
| Severity Important | Advisory/CVE(RHSA-2026:49701) Important: Red Hat JBoss Enterprise Application Platform 8.1.7 security update | Synopsis Important: Red Hat JBoss Enterprise Application Platform 8.1.7 security update | Date |
| Severity Important | Advisory/CVECVE-2026-67214 | Synopsis A flaw was found in nanoid (Nano ID), a JavaScript library used for generating unique identifiers. This vulnerability allows an attacker to cause a Denial of Service (DoS) by providing a negative size input to the customAlphabet or nanoid functions within the library's non-secure module. When a negative size is provided, these functions enter an infinite loop, causing the application to hang indefinitely and disrupting service availability. | Date |
Top resources
Get support
Support cases
Get answers quickly by opening a support case with us.
Live chat
Directly access our support engineers during weekday business hours.
Call or email
Speak directly with a Red Hat Support expert by phone or through email.