Back

MEDIUM

Undertow: unrestricted request storage leads to memory exhaustion

Published Nov 7, 2024

Description

A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of Service by sending crafted requests, leading the server to an OutofMemory error, exhausting the server's memory.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 7, 2024
Updated Nov 7, 2024
Reserved Apr 10, 2023
CISA Vulnrichment
Updated Nov 7, 2024
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Apr 4, 2024
GHSA-97CQ-F4JM-MV8H