CVE-2021-3690
- EPSS 0.33%
- Published 23.08.2022 16:15:09
- Last modified 21.11.2024 06:22:09
A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is availability.
CVE-2022-2053
- EPSS 0.53%
- Published 05.08.2022 16:15:11
- Last modified 21.11.2024 07:00:14
When a POST request comes through AJP and the request exceeds the max-post-size limit (maxEntitySize), Undertow's AjpServerRequestConduit implementation closes a connection without sending any response to the client/proxy. This behavior results in th...
CVE-2021-3629
- EPSS 0.1%
- Published 24.05.2022 19:15:09
- Last modified 21.11.2024 06:22:01
A flaw was found in Undertow. A potential security issue in flow control handling by the browser over http/2 may potentially cause overhead or a denial of service in the server. The highest threat from this vulnerability is availability. This flaw af...
CVE-2021-3597
- EPSS 0.17%
- Published 24.05.2022 19:15:09
- Last modified 21.11.2024 06:21:56
A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting in a denial of service. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2...
CVE-2019-19343
- EPSS 0.51%
- Published 23.03.2021 21:15:13
- Last modified 21.11.2024 04:34:36
A flaw was found in Undertow when using Remoting as shipped in Red Hat Jboss EAP before version 7.2.4. A memory leak in HttpOpenListener due to holding remote connections indefinitely may lead to denial of service. Versions before undertow 2.0.25.SP1...
CVE-2020-27782
- EPSS 0.31%
- Published 23.02.2021 19:15:13
- Last modified 21.11.2024 05:21:49
A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes could be triggered by an attacker using query strings with non-RFC compliant characters resulting in a denial of service. The highest threat from this vul...
CVE-2021-20220
- EPSS 0.31%
- Published 23.02.2021 18:15:13
- Last modified 21.11.2024 05:46:09
A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an a...
CVE-2020-10687
- EPSS 0.21%
- Published 23.09.2020 13:15:15
- Last modified 21.11.2024 04:55:51
A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, where HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an ...
CVE-2020-10705
- EPSS 0.38%
- Published 10.06.2020 20:15:12
- Last modified 21.11.2024 04:55:53
A flaw was discovered in Undertow in versions before Undertow 2.1.1.Final where certain requests to the "Expect: 100-continue" header may cause an out of memory error. This flaw may potentially lead to a denial of service.
CVE-2020-10719
- EPSS 0.17%
- Published 26.05.2020 16:15:12
- Last modified 21.11.2024 04:55:55
A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling.