Back

HIGH

undertow: Memory exhaustion issue in HttpReadListener via "Expect: 100-continue" header

Published Jun 10, 2020

Description

A flaw was discovered in Undertow in versions before Undertow 2.1.1.Final where certain requests to the "Expect: 100-continue" header may cause an out of memory error. This flaw may potentially lead to a denial of service.

Affected products

Remediation

Red Hat mitigation

There is currently no known mitigation for this security flaw.

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jun 10, 2020
Updated Aug 4, 2024
Reserved Mar 20, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date May 11, 2020
ENISA EUVD
Assigner redhat
Published Jun 10, 2020
Updated Aug 4, 2024
Exploited since n/a
EUVD-2021-0822 GHSA-G4CP-H53P-V3V8