Skip to main content

Vendor/product archive

redhat / undertow CVEs

Beta · best-effort

39 CVEs tagged to redhat / undertow3 Critical, 21 High, 14 Medium, 1 Low, 0 Unrated.

CVE-2026-28369

Published Mar 27, 2026

A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping…

CVSS 8.7 · High
evidence mentions
4
Buzz score
26.1

CVE-2026-28368

Published Mar 27, 2026

A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to…

CVSS 8.7 · High
evidence mentions
4
Buzz score
26.1

CVE-2026-28367

Published Mar 27, 2026

A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certai…

CVSS 8.7 · High
evidence mentions
4
Buzz score
26.1

CVE-2025-12543

Published Jan 7, 2026

A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host heade…

CVSS 9.6 · Critical
evidence mentions
16
Buzz score
39.8

CVE-2025-9784

Published Sep 2, 2025

A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset"…

CVSS 7.5 · High
evidence mentions
20
Buzz score
50.0

CVE-2024-1459

Published Feb 12, 2024

A path traversal vulnerability was found in Undertow. This issue may allow a remote attacker to append a specially-crafted sequence to an HTTP request for an application deployed…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3223

Published Sep 27, 2023

A flaw was found in undertow. Servlets annotated with @MultipartConfig may cause an OutOfMemoryError due to large multipart content. This may allow unauthorized users to cause rem…

CVSS 7.5 · High

CVE-2022-4492

Published Feb 23, 2023

The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by def…

CVSS 7.5 · High

CVE-2022-1259

Published Aug 31, 2022

A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of service in the server. This flaw exi…

CVSS 7.5 · High

CVE-2021-3690

Published Aug 23, 2022

A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The hi…

CVSS 7.5 · High

CVE-2021-3629

Published May 24, 2022

A flaw was found in Undertow. A potential security issue in flow control handling by the browser over http/2 may potentially cause overhead or a denial of service in the server. T…

CVSS 5.9 · Medium

CVE-2021-3597

Published May 24, 2022

A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting in a denial of service. The highest threat from this vulner…

CVSS 5.9 · Medium

CVE-2020-10719

Published May 26, 2020

A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advanta…

CVSS 6.5 · Medium

CVE-2020-1745

Published Apr 28, 2020

A file inclusion vulnerability was found in the AJP connector enabled with a default AJP configuration port of 8009 in Undertow version 2.0.29.Final and before and was fixed in 2.…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 39 CVEsPage 1 of 2