PT-2025-48972 · Undertow · Undertow

Published

2025-12-03

·

Updated

2026-03-19

·

CVE-2024-3884

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Undertow (affected versions not specified)
Description A flaw exists in Undertow that may lead to remote denial of service attacks. Specifically, when the server utilizes the FormEncodedDataDefinition.doParse(StreamSourceChannel) method to process large form data encoded with application/x-www-form-urlencoded, an OutOfMemory issue can occur. This allows unauthorized users to potentially trigger a remote denial of service (DoS) attack.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-3884
GHSA-6H4F-PJ3G-Q8FQ
OESA-2026-1431
RHSA-2025:22773
RHSA-2025:22775
RHSA-2025:3990
RHSA-2026:0383
RHSA-2026:0384
RHSA-2026:3889
RHSA-2026:3891
RHSA-2026:4915
RHSA-2026:4916
RHSA-2026:4917
RHSA-2026:6011
RHSA-2026:6012

Affected Products

Undertow