We found results for “”
CVE-2024-3884
Good to know:
Date: December 3, 2025
A flaw was found in Undertow that can cause remote denial of service attacks. When the server uses the FormEncodedDataDefinition.doParse(StreamSourceChannel) method to parse large form data encoding with application/x-www-form-urlencoded, the method will cause an OutOfMemory issue. This flaw allows unauthorized users to cause a remote denial of service (DoS) attack.
Severity Score
Related Resources (16)
Severity Score
Weakness Type (CWE)
Improper Input Validation
CWE-20Top Fix
Upgrade Version
Upgrade to version io.undertow:undertow-core:2.3.21.Final;io.undertow:undertow-core:https://github.com/advisories/GHSA-6h4f-pj3g-q8fq
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | NONE |
| Integrity (I): | NONE |
| Availability (A): | HIGH |
Vulnerabilities
Projects
Contact Us


