Skip to main content

Vendor/product archive

redhat / jboss_enterprise_application_platform CVEs

Beta · best-effort

239 CVEs tagged to redhat / jboss_enterprise_application_platform31 Critical, 84 High, 105 Medium, 19 Low, 0 Unrated.

CVE-2026-28369

Published Mar 27, 2026

A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping…

CVSS 8.7 · High
evidence mentions
4
Buzz score
26.1

CVE-2026-28368

Published Mar 27, 2026

A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to…

CVSS 8.7 · High
evidence mentions
4
Buzz score
26.1

CVE-2026-28367

Published Mar 27, 2026

A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certai…

CVSS 8.7 · High
evidence mentions
4
Buzz score
26.1

CVE-2025-12543

Published Jan 7, 2026

A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host heade…

CVSS 9.6 · Critical
evidence mentions
16
Buzz score
39.8

CVE-2025-9784

Published Sep 2, 2025

A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset"…

CVSS 7.5 · High
evidence mentions
20
Buzz score
50.0

CVE-2024-7885

Published Aug 21, 2024

A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue occurs when the parseProxyPro…

CVSS 7.5 · High

CVE-2024-1635

Published Feb 19, 2024

A vulnerability was found in Undertow. This vulnerability impacts a server that supports the wildfly-http-client protocol. Whenever a malicious user opens and closes a connection…

CVSS 7.5 · High

CVE-2023-3223

Published Sep 27, 2023

A flaw was found in undertow. Servlets annotated with @MultipartConfig may cause an OutOfMemoryError due to large multipart content. This may allow unauthorized users to cause rem…

CVSS 7.5 · High
Showing 1-25 of 239 CVEsPage 1 of 10