HIGH7.5
GHSA-6h4f-pj3g-q8fq
Undertow OutOfMemory when parsing form data encoding with application/x-www-form-urlencoded
Quick fix
GHSA-6h4f-pj3g-q8fq — io.undertow:undertow-core: upgrade to the fixed version with the command below.
# pom.xml: bump <version>2.2.39.Final</version> for io.undertow:undertow-coreDetails
A flaw was found in Undertow that can cause remote denial of service attacks. When the server uses the FormEncodedDataDefinition.doParse(StreamSourceChannel) method to parse large form data encoding with application/x-www-form-urlencoded, the method will cause an OutOfMemory issue. This flaw allows unauthorized users to cause a remote denial of service (DoS) attack.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/io.undertow:undertow-core
Introduced in:
0Fixed in: 2.2.39.FinalFix
# pom.xml: bump <version>2.2.39.Final</version> for io.undertow:undertow-coreMaven/io.undertow:undertow-core
Introduced in:
2.4.0.Alpha1Fixed in: 2.4.0.Beta1Fix
# pom.xml: bump <version>2.4.0.Beta1</version> for io.undertow:undertow-coreMaven/io.undertow:undertow-core
Introduced in:
2.3.0.Alpha1Fixed in: 2.3.21.FinalFix
# pom.xml: bump <version>2.3.21.Final</version> for io.undertow:undertow-coreReferences
- https://nvd.nist.gov/vuln/detail/CVE-2024-3884[ADVISORY]
- https://github.com/undertow-io/undertow/pull/1894[WEB]
- https://github.com/undertow-io/undertow/pull/1882[WEB]
- https://github.com/undertow-io/undertow/pull/1860[WEB]
- https://github.com/undertow-io/undertow/pull/1856[WEB]
- https://github.com/undertow-io/undertow/commit/cb854c779b9e2368c3c274ebd7217c8e75d505be[WEB]
- https://github.com/undertow-io/undertow/releases/tag/2.4.0.Beta1[WEB]
- https://github.com/undertow-io/undertow/releases/tag/2.3.21.Final[WEB]
- https://github.com/undertow-io/undertow/releases/tag/2.2.39.Final[WEB]
- https://github.com/undertow-io/undertow[PACKAGE]
- https://bugzilla.redhat.com/show_bug.cgi?id=2275287[WEB]
- https://access.redhat.com/security/cve/CVE-2024-3884[WEB]
- https://access.redhat.com/errata/RHSA-2026:6012[WEB]
- https://access.redhat.com/errata/RHSA-2026:6011[WEB]
- https://access.redhat.com/errata/RHSA-2026:4924[WEB]
- https://access.redhat.com/errata/RHSA-2026:4917[WEB]
- https://access.redhat.com/errata/RHSA-2026:4916[WEB]
- https://access.redhat.com/errata/RHSA-2026:4915[WEB]
- https://access.redhat.com/errata/RHSA-2026:3892[WEB]
- https://access.redhat.com/errata/RHSA-2026:3891[WEB]
- https://access.redhat.com/errata/RHSA-2026:3889[WEB]
- https://access.redhat.com/errata/RHSA-2026:0386[WEB]
- https://access.redhat.com/errata/RHSA-2026:0384[WEB]
- https://access.redhat.com/errata/RHSA-2026:0383[WEB]
- https://access.redhat.com/errata/RHSA-2025:3992[WEB]
- https://access.redhat.com/errata/RHSA-2025:3990[WEB]
- https://access.redhat.com/errata/RHSA-2025:22777[WEB]
- https://access.redhat.com/errata/RHSA-2025:22775[WEB]
- https://access.redhat.com/errata/RHSA-2025:22773[WEB]