Undertow: out-of-memory error after several closed connections with wildfly-http-client protocol
Published Feb 19, 2024
8.7
HIGHCVSS 4.0
EPSS 4.57%
Description
A vulnerability was found in Undertow. This vulnerability impacts a server that supports the wildfly-http-client protocol. Whenever a malicious user opens and closes a connection with the HTTP port of the server and then closes the connection immediately, the server will end with both memory and open file limits exhausted at some point, depending on the amount of memory available. At HTTP upgrade to remoting, the WriteTimeoutStreamSinkConduit leaks connections if RemotingConnection is closed by Remoting ServerConnectionOpenListener. Because the remoting connection originates in Undertow as part of the HTTP upgrade, there is an external layer to the remoting connection. This connection is unaware of the outermost layer when closing the connection during the connection opening procedure. Hence, the Undertow WriteTimeoutStreamSinkConduit is not notified of the closed connection in this scenario. Because WriteTimeoutStreamSinkConduit creates a timeout task, the whole dependency tree leaks via that task, which is added to XNIO WorkerThread. So, the workerThread points to the Undertow conduit, which contains the connections and causes the leak.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat Process Automation 7 | affected |
| |||
| Red Hat | Red Hat build of Apache Camel for Spring Boot 4 | affected |
|
Configuration 1
- n/a
- n/a
- n/a
- n/a
Configuration 2
- 1.0
- n/a
- 7.4
- 4.11
- 4.12
- 4.9
- 4.10
- 4.9
- 4.10
- n/a
- 7.6
No data.
RHEL-8 based Middleware Containers
rh-sso-7/sso76-openshift-rhel8:7.6-46
Fixed · RHSA-2024:1864
RHSSO 7.6.8
undertow
Fixed · RHSA-2024:1866
Red Hat Fuse 7.13.0
n/a
Fixed · RHSA-2024:3354
Red Hat JBoss Enterprise Application Platform
io.undertow/undertow-core:2.2.30.SP1-redhat-00001
Fixed · RHSA-2024:1677
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-activemq-artemis-0:1.5.5.016-1.redhat_00001.1.ep7.el7
Fixed · RHSA-2025:4226
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-artemis-native-1:1.5.5.016-1.redhat_00001.1.ep7.el7
Fixed · RHSA-2025:4226
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-jboss-xnio-base-0:3.5.11-1.Final_redhat_00001.1.ep7.el7
Fixed · RHSA-2025:4226
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-jsoup-0:1.14.2-1.redhat_00002.1.ep7.el7
Fixed · RHSA-2025:4226
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-undertow-0:1.4.18-14.SP13_redhat_00001.1.ep7.el7
Fixed · RHSA-2025:4226
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-wildfly-0:7.1.10-2.GA_redhat_00002.1.ep7.el7
Fixed · RHSA-2025:4226
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-woodstox-core-0:5.0.3-2.redhat_00002.1.ep7.el7
Fixed · RHSA-2025:4226
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-xml-security-0:2.0.10-2.redhat_00002.1.ep7.el7
Fixed · RHSA-2025:4226
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-jackson-annotations-0:2.10.4-3.redhat_00006.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-jackson-core-0:2.10.4-3.redhat_00006.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-jackson-databind-0:2.10.4-5.redhat_00006.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-jackson-jaxrs-providers-0:2.10.4-3.redhat_00006.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-jackson-modules-base-0:2.10.4-5.redhat_00006.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-jackson-modules-java8-0:2.10.4-2.redhat_00006.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-jboss-server-migration-0:1.7.2-16.Final_redhat_00017.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-netty-0:4.1.63-5.Final_redhat_00003.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-undertow-0:2.0.41-4.SP5_redhat_00001.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-wildfly-0:7.3.14-3.GA_redhat_00002.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-wildfly-elytron-0:1.10.17-1.Final_redhat_00001.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8
eap7-undertow-0:2.2.30-1.SP1_redhat_00001.1.el8eap
Fixed · RHSA-2024:1675
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9
eap7-undertow-0:2.2.30-1.SP1_redhat_00001.1.el9eap
Fixed · RHSA-2024:1676
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7
eap7-undertow-0:2.2.30-1.SP1_redhat_00001.1.el7eap
Fixed · RHSA-2024:1674
Red Hat Single Sign-On 7.6 for RHEL 7
rh-sso7-keycloak-0:18.0.13-1.redhat_00001.1.el7sso
Fixed · RHSA-2024:1860
Red Hat Single Sign-On 7.6 for RHEL 8
rh-sso7-keycloak-0:18.0.13-1.redhat_00001.1.el8sso
Fixed · RHSA-2024:1861
Red Hat Single Sign-On 7.6 for RHEL 9
rh-sso7-keycloak-0:18.0.13-1.redhat_00001.1.el9sso
Fixed · RHSA-2024:1862
Red Hat build of Apache Camel 4.4.1 for Spring Boot 3.2
n/a
Fixed · RHSA-2024:4884
OpenShift Serverless
undertow
Not affected
Red Hat Build of Keycloak
undertow
Not affected
Red Hat Data Grid 8
undertow
Not affected
Red Hat Integration Camel K 1
undertow
Not affected
Red Hat Integration Camel Quarkus 2
undertow
Not affected
Red Hat JBoss Data Grid 7
undertow
Out of support scope
Red Hat JBoss Enterprise Application Platform 8
undertow-core
Not affected
Red Hat JBoss Fuse Service Works 6
undertow
Out of support scope
Red Hat Process Automation 7
undertow
Will not fix
Red Hat build of Apache Camel 4 for Quarkus 3
undertow
Not affected
Red Hat build of Apache Camel for Spring Boot 3
undertow
Not affected
Red Hat build of Apache Camel for Spring Boot 4
undertow
Affected
Red Hat build of Apicurio Registry 2
undertow
Not affected
Red Hat build of OptaPlanner 8
undertow
Not affected
Red Hat build of Quarkus
quarkus-undertow
Not affected
Red Hat build of Quarkus
quarkus-undertow
Not affected
streams for Apache Kafka
undertow
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| RHEL-8 based Middleware Containers | rh-sso-7/sso76-openshift-rhel8:7.6-46 | Fixed | RHSA-2024:1864 |
| RHSSO 7.6.8 | undertow | Fixed | RHSA-2024:1866 |
| Red Hat Fuse 7.13.0 | n/a | Fixed | RHSA-2024:3354 |
| Red Hat JBoss Enterprise Application Platform | io.undertow/undertow-core:2.2.30.SP1-redhat-00001 | Fixed | RHSA-2024:1677 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-activemq-artemis-0:1.5.5.016-1.redhat_00001.1.ep7.el7 | Fixed | RHSA-2025:4226 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-artemis-native-1:1.5.5.016-1.redhat_00001.1.ep7.el7 | Fixed | RHSA-2025:4226 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-jboss-xnio-base-0:3.5.11-1.Final_redhat_00001.1.ep7.el7 | Fixed | RHSA-2025:4226 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-jsoup-0:1.14.2-1.redhat_00002.1.ep7.el7 | Fixed | RHSA-2025:4226 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-undertow-0:1.4.18-14.SP13_redhat_00001.1.ep7.el7 | Fixed | RHSA-2025:4226 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-wildfly-0:7.1.10-2.GA_redhat_00002.1.ep7.el7 | Fixed | RHSA-2025:4226 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-woodstox-core-0:5.0.3-2.redhat_00002.1.ep7.el7 | Fixed | RHSA-2025:4226 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-xml-security-0:2.0.10-2.redhat_00002.1.ep7.el7 | Fixed | RHSA-2025:4226 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-jackson-annotations-0:2.10.4-3.redhat_00006.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-jackson-core-0:2.10.4-3.redhat_00006.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-jackson-databind-0:2.10.4-5.redhat_00006.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-jackson-jaxrs-providers-0:2.10.4-3.redhat_00006.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-jackson-modules-base-0:2.10.4-5.redhat_00006.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-jackson-modules-java8-0:2.10.4-2.redhat_00006.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-jboss-server-migration-0:1.7.2-16.Final_redhat_00017.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-netty-0:4.1.63-5.Final_redhat_00003.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-undertow-0:2.0.41-4.SP5_redhat_00001.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-wildfly-0:7.3.14-3.GA_redhat_00002.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-wildfly-elytron-0:1.10.17-1.Final_redhat_00001.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | eap7-undertow-0:2.2.30-1.SP1_redhat_00001.1.el8eap | Fixed | RHSA-2024:1675 |
| Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 | eap7-undertow-0:2.2.30-1.SP1_redhat_00001.1.el9eap | Fixed | RHSA-2024:1676 |
| Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 | eap7-undertow-0:2.2.30-1.SP1_redhat_00001.1.el7eap | Fixed | RHSA-2024:1674 |
| Red Hat Single Sign-On 7.6 for RHEL 7 | rh-sso7-keycloak-0:18.0.13-1.redhat_00001.1.el7sso | Fixed | RHSA-2024:1860 |
| Red Hat Single Sign-On 7.6 for RHEL 8 | rh-sso7-keycloak-0:18.0.13-1.redhat_00001.1.el8sso | Fixed | RHSA-2024:1861 |
| Red Hat Single Sign-On 7.6 for RHEL 9 | rh-sso7-keycloak-0:18.0.13-1.redhat_00001.1.el9sso | Fixed | RHSA-2024:1862 |
| Red Hat build of Apache Camel 4.4.1 for Spring Boot 3.2 | n/a | Fixed | RHSA-2024:4884 |
| OpenShift Serverless | undertow | Not affected | n/a |
| Red Hat Build of Keycloak | undertow | Not affected | n/a |
| Red Hat Data Grid 8 | undertow | Not affected | n/a |
| Red Hat Integration Camel K 1 | undertow | Not affected | n/a |
| Red Hat Integration Camel Quarkus 2 | undertow | Not affected | n/a |
| Red Hat JBoss Data Grid 7 | undertow | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | undertow-core | Not affected | n/a |
| Red Hat JBoss Fuse Service Works 6 | undertow | Out of support scope | n/a |
| Red Hat Process Automation 7 | undertow | Will not fix | n/a |
| Red Hat build of Apache Camel 4 for Quarkus 3 | undertow | Not affected | n/a |
| Red Hat build of Apache Camel for Spring Boot 3 | undertow | Not affected | n/a |
| Red Hat build of Apache Camel for Spring Boot 4 | undertow | Affected | n/a |
| Red Hat build of Apicurio Registry 2 | undertow | Not affected | n/a |
| Red Hat build of OptaPlanner 8 | undertow | Not affected | n/a |
| Red Hat build of Quarkus | quarkus-undertow | Not affected | n/a |
| Red Hat build of Quarkus | quarkus-undertow | Not affected | n/a |
| streams for Apache Kafka | undertow | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
No mitigation is currently available for this vulnerability. However, there might be some protections, such as request limits by a load balancer in front of JBoss EAP/Wildfly or even Undertow, that could minimize the impact.
Red Hat statement
This is rated as Important due to the fact that this might be an unauthenticated remote issue exploited by a malicious user, causing a denial of service (DoS) to the affected server.
Red Hat mitigation
No mitigation is currently available for this vulnerability. However, there might be some protections, such as request limits by a load balancer in front of JBoss EAP/Wildfly or even Undertow, that could minimize the impact.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Feb 22, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2024–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (49 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 4.57% (0.04572) | 91.33th | v5 (v2026.06.15) |
| Jun 15, 2026 | 4.57% (0.04572) | 90.37th | v5 (v2026.06.15) |
| Mar 21, 2026 | 22.69% (0.22688) | 95.80th | v4 (v2025.03.14) |
| Mar 4, 2026 | 8.33% (0.08330) | 92.12th | v4 (v2025.03.14) |
| Mar 1, 2026 | 1.06% (0.01061) | 77.45th | v4 (v2025.03.14) |
| Feb 4, 2026 | 8.33% (0.08330) | 92.06th | v4 (v2025.03.14) |
| Feb 1, 2026 | 1.06% (0.01061) | 77.34th | v4 (v2025.03.14) |
| Jan 4, 2026 | 8.33% (0.08330) | 91.99th | v4 (v2025.03.14) |
| Jan 1, 2026 | 1.06% (0.01061) | 77.28th | v4 (v2025.03.14) |
| Dec 4, 2025 | 8.33% (0.08330) | 91.93th | v4 (v2025.03.14) |
| Dec 1, 2025 | 1.06% (0.01061) | 77.10th | v4 (v2025.03.14) |
| Nov 21, 2025 | 8.33% (0.08330) | 91.91th | v4 (v2025.03.14) |
| Nov 18, 2025 | 62.81% (0.62809) | 98.36th | v4 (v2025.03.14) |
| Nov 4, 2025 | 8.33% (0.08330) | 91.88th | v4 (v2025.03.14) |
| Nov 1, 2025 | 1.06% (0.01061) | 77.06th | v4 (v2025.03.14) |
| Oct 4, 2025 | 8.33% (0.08330) | 91.92th | v4 (v2025.03.14) |
| Oct 1, 2025 | 1.06% (0.01061) | 76.98th | v4 (v2025.03.14) |
| Sep 24, 2025 | 8.33% (0.08330) | 91.95th | v4 (v2025.03.14) |
| Sep 4, 2025 | 10.47% (0.10466) | 92.97th | v4 (v2025.03.14) |
| Sep 1, 2025 | 1.06% (0.01061) | 76.89th | v4 (v2025.03.14) |
| Aug 4, 2025 | 8.33% (0.08330) | 91.90th | v4 (v2025.03.14) |
| Aug 1, 2025 | 1.06% (0.01061) | 76.83th | v4 (v2025.03.14) |
| Jul 26, 2025 | 8.33% (0.08330) | 91.87th | v4 (v2025.03.14) |
| Jul 4, 2025 | 10.72% (0.10719) | 92.99th | v4 (v2025.03.14) |
| Jul 1, 2025 | 1.20% (0.01200) | 78.05th | v4 (v2025.03.14) |
| Jun 6, 2025 | 10.47% (0.10466) | 92.82th | v4 (v2025.03.14) |
| Jun 1, 2025 | 1.88% (0.01881) | 82.30th | v4 (v2025.03.14) |
| May 29, 2025 | 8.33% (0.08330) | 91.80th | v4 (v2025.03.14) |
| May 27, 2025 | 1.44% (0.01435) | 79.70th | v4 (v2025.03.14) |
| May 8, 2025 | 8.33% (0.08330) | 91.79th | v4 (v2025.03.14) |
| May 4, 2025 | 5.96% (0.05955) | 90.12th | v4 (v2025.03.14) |
| May 1, 2025 | 1.27% (0.01268) | 78.44th | v4 (v2025.03.14) |
| Apr 17, 2025 | 5.96% (0.05955) | 90.10th | v4 (v2025.03.14) |
| Apr 16, 2025 | 1.27% (0.01268) | 78.32th | v4 (v2025.03.14) |
| Apr 15, 2025 | 5.96% (0.05955) | 90.08th | v4 (v2025.03.14) |
| Apr 14, 2025 | 11.05% (0.11046) | 92.81th | v4 (v2025.03.14) |
| Apr 9, 2025 | 63.28% (0.63277) | 98.26th | v4 (v2025.03.14) |
| Apr 8, 2025 | 11.05% (0.11046) | 92.82th | v4 (v2025.03.14) |
| Apr 5, 2025 | 63.28% (0.63277) | 98.26th | v4 (v2025.03.14) |
| Apr 4, 2025 | 11.05% (0.11046) | 92.83th | v4 (v2025.03.14) |
| Mar 30, 2025 | 63.28% (0.63277) | 98.25th | v4 (v2025.03.14) |
| Mar 29, 2025 | 71.84% (0.71843) | 98.32th | v4 (v2025.03.14) |
| Mar 20, 2025 | 63.28% (0.63277) | 98.28th | v4 (v2025.03.14) |
| Mar 17, 2025 | 24.99% (0.24988) | 95.70th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00044) | 15.00th | v3 (v2023.03.01) |
| Apr 18, 2024 | 0.04% (0.00045) | 13.32th | v3 (v2023.03.01) |
| Apr 5, 2024 | 0.04% (0.00044) | 8.95th | v3 (v2023.03.01) |
| Mar 23, 2024 | 0.04% (0.00045) | 12.99th | v3 (v2023.03.01) |
| Feb 20, 2024 | 0.04% (0.00043) | 6.73th | v3 (v2023.03.01) |
References (21)
- https://access.redhat.com/errata/RHSA-2024:1674 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:1675 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:1676 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:1677 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:1860 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:1861 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:1862 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:1864 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:1866 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:3354 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:4884 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:4226 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:9583 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2024-1635 vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2264928 issue-trackingx_refsource_REDHATThird Party AdvisoryIssue Tracking
- https://github.com/advisories/GHSA-w6qf-42m7-vh68 Advisory
- https://github.com/undertow-io/undertow/commit/3cdb104e225f34547ce9fd6eb8799eb68e040f19
- https://github.com/undertow-io/undertow/commit/7d388c5aae9b82afb63f24e3b6a2044838dfb4de
- https://nvd.nist.gov/vuln/detail/CVE-2024-1635
- https://security.netapp.com/advisory/ntap-20240322-0007 Vendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2024-1635
Change history (0)
No recorded changes yet.