Modcluster-core: mod_cluster advertise listener: unauthenticated dos via crafted multicast datagram
Published Aug 19, 2026
4.3
MEDIUMCVSS 3.1
EPSS 1.03%
Description
A flaw was found in mod_cluster's AdvertiseListenerImpl (org.jboss.modcluster core module). A single crafted UDP multicast datagram with a valid HTTP status line and a "Server:" header but without the "Date:", "Digest:", and "Sequence:" headers triggers a NullPointerException in verifyDigest() that is not caught by the worker thread's exception handler. This causes the advertise listener thread to terminate permanently. The failure is silent (isListening() continues to return true) and persists until the node is restarted. The crash occurs before the AdvertiseSecurityKey comparison, so deployments with a configured security key are still affected.
Affected products
-
-
- Vendor Red Hat Product Red Hat JBoss Enterprise Application Platform Expansion Pack Defaultaffected
-
-
-
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 | affected |
| |||
| Red Hat | Red Hat JBoss Enterprise Application Platform 8 | affected |
| |||
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | affected |
| |||
| Red Hat | Red Hat JBoss Web Server 6 | affected |
| |||
| Red Hat | Red Hat JBoss Web Server 7 | affected |
| |||
| Red Hat | Red Hat Single Sign-On 7 | affected |
|
No data.
No data.
Red Hat JBoss Enterprise Application Platform 7
mod_cluster-core
Fix deferred
Red Hat JBoss Enterprise Application Platform 8
mod_cluster-core
Fix deferred
Red Hat JBoss Enterprise Application Platform Expansion Pack
mod_cluster-core
Fix deferred
Red Hat JBoss Web Server 5
mod_cluster-core
Out of support scope
Red Hat JBoss Web Server 6
mod_cluster-core
Affected
Red Hat JBoss Web Server 7
mod_cluster-core
Affected
Red Hat Single Sign-On 7
mod_cluster-core
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat JBoss Enterprise Application Platform 7 | mod_cluster-core | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | mod_cluster-core | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | mod_cluster-core | Fix deferred | n/a |
| Red Hat JBoss Web Server 5 | mod_cluster-core | Out of support scope | n/a |
| Red Hat JBoss Web Server 6 | mod_cluster-core | Affected | n/a |
| Red Hat JBoss Web Server 7 | mod_cluster-core | Affected | n/a |
| Red Hat Single Sign-On 7 | mod_cluster-core | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Disable multicast-based proxy advertisement and use static proxy configuration instead. When advertisement must be enabled, ensure the multicast network segment (default 224.0.1.105:23364) is properly isolated and not accessible from untrusted network segments.
Red Hat mitigation
Disable multicast-based proxy advertisement and use static proxy configuration instead. When advertisement must be enabled, ensure the multicast network segment (default 224.0.1.105:23364) is properly isolated and not accessible from untrusted network segments.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Aug 20, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Aug–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.03% (0.01034) | 62.54th | v5 (v2026.06.15) |
| Aug 20, 2026 | 0.84% (0.00841) | 55.11th | v5 (v2026.06.15) |
References (4)
- https://access.redhat.com/security/cve/CVE-2026-76166 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2510883 issue-trackingx_refsource_REDHATIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2026-76166
- https://www.cve.org/CVERecord?id=CVE-2026-76166
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-76166 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2510883 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-76166 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-76166 |
Change history (0)
No recorded changes yet.