Undertow · Undertow · CVE-2021-3859
**Name of the Vulnerable Software and Affected Versions**
Undertow versions prior to 2.2.15 Final
**Description**
A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks.
**Recommendations**
For versions prior to 2.2.15 Final, update to version 2.2.15 Final or later to resolve the issue. As a temporary workaround, consider restricting access to HTTP2 calls to minimize the risk of exploitation.