VDB
Sign up
HIGH7.5

GHSA-6h4f-pj3g-q8fq

Undertow OutOfMemory when parsing form data encoding with application/x-www-form-urlencoded

Quick fix

GHSA-6h4f-pj3g-q8fq — io.undertow:undertow-core: upgrade to the fixed version with the command below.

# pom.xml: bump <version>2.2.39.Final</version> for io.undertow:undertow-core

Details

A flaw was found in Undertow that can cause remote denial of service attacks. When the server uses the FormEncodedDataDefinition.doParse(StreamSourceChannel) method to parse large form data encoding with application/x-www-form-urlencoded, the method will cause an OutOfMemory issue. This flaw allows unauthorized users to cause a remote denial of service (DoS) attack.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/io.undertow:undertow-core
Introduced in: 0Fixed in: 2.2.39.Final
Fix# pom.xml: bump <version>2.2.39.Final</version> for io.undertow:undertow-core
Maven/io.undertow:undertow-core
Introduced in: 2.4.0.Alpha1Fixed in: 2.4.0.Beta1
Fix# pom.xml: bump <version>2.4.0.Beta1</version> for io.undertow:undertow-core
Maven/io.undertow:undertow-core
Introduced in: 2.3.0.Alpha1Fixed in: 2.3.21.Final
Fix# pom.xml: bump <version>2.3.21.Final</version> for io.undertow:undertow-core

References