Undertow
Red Hat · 39 CVEs
Undertow: undertow: request smuggling via malformed http request headers
Mar 27, 2026
Undertow: undertow: request smuggling via `\r\r\r` as a header block terminator
Mar 27, 2026
Undertow: undertow: request smuggling via inconsistent header parsing
Mar 27, 2026
Undertow-core: undertow http server fails to reject malformed host headers leading to potential cache poisoning and ssrf
Jan 7, 2026
Undertow: undertow madeyoureset http/2 ddos vulnerability
Sep 2, 2025
Undertow: directory traversal vulnerability
Feb 12, 2024
Undertow: ajp request closes connection exceeding maxrequestsize
Dec 12, 2023
Undertow: outofmemoryerror due to @multipartconfig handling
Sep 27, 2023
Undertow: infinite loop in sslconduit during close
Sep 14, 2023
undertow: Server identity in https connection is not checked by the undertow client
Feb 23, 2023
Undertow: DoS can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations
Sep 1, 2022
undertow: Double AJP response for 400 from EAP 7 results in CPING failures
Aug 31, 2022
undertow: potential security issue in flow control over HTTP/2 may lead to DOS(incomplete fix for CVE-2021-3629)
Aug 31, 2022
undertow: client side invocation timeout raised when calling over HTTP2
Aug 26, 2022
undertow: buffer leak on incoming websocket PONG message may lead to DoS
Aug 23, 2022
undertow: Large AJP request may cause DoS
Aug 5, 2022
undertow: HTTP2SourceChannel fails to write final frame under some circumstances may lead to DoS
May 24, 2022
undertow: potential security issue in flow control over HTTP/2 may lead to DOS
May 24, 2022
Undertow: Memory Leak in Undertow HttpOpenListener due to holding remoting connections indefinitely
Mar 23, 2021
undertow: special character in query results in server errors
Feb 23, 2021
undertow: Possible regression in fix for CVE-2020-10687
Feb 23, 2021
Undertow: Incomplete fix for CVE-2017-2666 due to permitting invalid characters in HTTP requests
Sep 23, 2020
undertow: Memory exhaustion issue in HttpReadListener via "Expect: 100-continue" header
Jun 10, 2020
undertow: invalid HTTP request with large chunk size
May 26, 2020
undertow: AJP File Read/Inclusion Vulnerability
Apr 28, 2020
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-28369 | Undertow: undertow: request smuggling via malformed http request headers | CRITICAL | 0.89% | Mar 27, 2026 |
| CVE-2026-28367 | Undertow: undertow: request smuggling via `\r\r\r` as a header block terminator | CRITICAL | 0.89% | Mar 27, 2026 |
| CVE-2026-28368 | Undertow: undertow: request smuggling via inconsistent header parsing | CRITICAL | 0.89% | Mar 27, 2026 |
| CVE-2025-12543 | Undertow-core: undertow http server fails to reject malformed host headers leading to potential cache poisoning and ssrf | CRITICAL | 1.33% | Jan 7, 2026 |
| CVE-2025-9784 | Undertow: undertow madeyoureset http/2 ddos vulnerability | HIGH | 2.33% | Sep 2, 2025 |
| CVE-2024-1459 | Undertow: directory traversal vulnerability | MEDIUM | 1.71% | Feb 12, 2024 |
| CVE-2023-5379 | Undertow: ajp request closes connection exceeding maxrequestsize | HIGH | 1.03% | Dec 12, 2023 |
| CVE-2023-3223 | Undertow: outofmemoryerror due to @multipartconfig handling | HIGH | 2.66% | Sep 27, 2023 |
| CVE-2023-1108 | Undertow: infinite loop in sslconduit during close | HIGH | 1.77% | Sep 14, 2023 |
| CVE-2022-4492 | undertow: Server identity in https connection is not checked by the undertow client | CRITICAL | 0.60% | Feb 23, 2023 |
| CVE-2022-2764 | Undertow: DoS can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations | MEDIUM | 0.89% | Sep 1, 2022 |
| CVE-2022-1319 | undertow: Double AJP response for 400 from EAP 7 results in CPING failures | HIGH | 1.59% | Aug 31, 2022 |
| CVE-2022-1259 | undertow: potential security issue in flow control over HTTP/2 may lead to DOS(incomplete fix for CVE-2021-3629) | HIGH | 1.31% | Aug 31, 2022 |
| CVE-2021-3859 | undertow: client side invocation timeout raised when calling over HTTP2 | HIGH | 1.64% | Aug 26, 2022 |
| CVE-2021-3690 | undertow: buffer leak on incoming websocket PONG message may lead to DoS | HIGH | 1.68% | Aug 23, 2022 |
| CVE-2022-2053 | undertow: Large AJP request may cause DoS | HIGH | 1.06% | Aug 5, 2022 |
| CVE-2021-3597 | undertow: HTTP2SourceChannel fails to write final frame under some circumstances may lead to DoS | MEDIUM | 1.14% | May 24, 2022 |
| CVE-2021-3629 | undertow: potential security issue in flow control over HTTP/2 may lead to DOS | HIGH | 1.32% | May 24, 2022 |
| CVE-2019-19343 | Undertow: Memory Leak in Undertow HttpOpenListener due to holding remoting connections indefinitely | HIGH | 1.63% | Mar 23, 2021 |
| CVE-2020-27782 | undertow: special character in query results in server errors | HIGH | 1.38% | Feb 23, 2021 |
| CVE-2021-20220 | undertow: Possible regression in fix for CVE-2020-10687 | MEDIUM | 1.20% | Feb 23, 2021 |
| CVE-2020-10687 | Undertow: Incomplete fix for CVE-2017-2666 due to permitting invalid characters in HTTP requests | MEDIUM | 1.23% | Sep 23, 2020 |
| CVE-2020-10705 | undertow: Memory exhaustion issue in HttpReadListener via "Expect: 100-continue" header | HIGH | 1.19% | Jun 10, 2020 |
| CVE-2020-10719 | undertow: invalid HTTP request with large chunk size | MEDIUM | 0.98% | May 26, 2020 |
| CVE-2020-1745 | undertow: AJP File Read/Inclusion Vulnerability | CRITICAL | 4.96% | Apr 28, 2020 |
Showing 1 to 25 of 39 CVEs