Undertow

Red Hat · 39 CVEs

CVE-2026-28369
CRITICAL

Undertow: undertow: request smuggling via malformed http request headers

Mar 27, 2026

CVE-2026-28367
CRITICAL

Undertow: undertow: request smuggling via `\r\r\r` as a header block terminator

Mar 27, 2026

CVE-2026-28368
CRITICAL

Undertow: undertow: request smuggling via inconsistent header parsing

Mar 27, 2026

CVE-2025-12543
CRITICAL

Undertow-core: undertow http server fails to reject malformed host headers leading to potential cache poisoning and ssrf

Jan 7, 2026

CVE-2025-9784
HIGH

Undertow: undertow madeyoureset http/2 ddos vulnerability

Sep 2, 2025

CVE-2024-1459
MEDIUM

Undertow: directory traversal vulnerability

Feb 12, 2024

CVE-2023-5379
HIGH

Undertow: ajp request closes connection exceeding maxrequestsize

Dec 12, 2023

CVE-2023-3223
HIGH

Undertow: outofmemoryerror due to @multipartconfig handling

Sep 27, 2023

CVE-2023-1108
HIGH

Undertow: infinite loop in sslconduit during close

Sep 14, 2023

CVE-2022-4492
CRITICAL

undertow: Server identity in https connection is not checked by the undertow client

Feb 23, 2023

CVE-2022-2764
MEDIUM

Undertow: DoS can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations

Sep 1, 2022

CVE-2022-1319
HIGH

undertow: Double AJP response for 400 from EAP 7 results in CPING failures

Aug 31, 2022

CVE-2022-1259
HIGH

undertow: potential security issue in flow control over HTTP/2 may lead to DOS(incomplete fix for CVE-2021-3629)

Aug 31, 2022

CVE-2021-3859
HIGH

undertow: client side invocation timeout raised when calling over HTTP2

Aug 26, 2022

CVE-2021-3690
HIGH

undertow: buffer leak on incoming websocket PONG message may lead to DoS

Aug 23, 2022

CVE-2022-2053
HIGH

undertow: Large AJP request may cause DoS

Aug 5, 2022

CVE-2021-3597
MEDIUM

undertow: HTTP2SourceChannel fails to write final frame under some circumstances may lead to DoS

May 24, 2022

CVE-2021-3629
HIGH

undertow: potential security issue in flow control over HTTP/2 may lead to DOS

May 24, 2022

CVE-2019-19343
HIGH

Undertow: Memory Leak in Undertow HttpOpenListener due to holding remoting connections indefinitely

Mar 23, 2021

CVE-2020-27782
HIGH

undertow: special character in query results in server errors

Feb 23, 2021

CVE-2021-20220
MEDIUM

undertow: Possible regression in fix for CVE-2020-10687

Feb 23, 2021

CVE-2020-10687
MEDIUM

Undertow: Incomplete fix for CVE-2017-2666 due to permitting invalid characters in HTTP requests

Sep 23, 2020

CVE-2020-10705
HIGH

undertow: Memory exhaustion issue in HttpReadListener via "Expect: 100-continue" header

Jun 10, 2020

CVE-2020-10719
MEDIUM

undertow: invalid HTTP request with large chunk size

May 26, 2020

CVE-2020-1745
CRITICAL

undertow: AJP File Read/Inclusion Vulnerability

Apr 28, 2020

Showing 1 to 25 of 39 CVEs