Bug#1123001: undertow: CVE-2024-3884

Moritz Mühlenhoff jmm at inutil.org
Mon Dec 15 19:13:05 GMT 2025


Source: undertow
X-Debbugs-CC: team at security.debian.org
Severity: important
Tags: security

Hi,

The following vulnerability was published for undertow.

CVE-2024-3884[0]:
| A flaw was found in Undertow that can cause remote denial of service
| attacks. When the server uses the
| FormEncodedDataDefinition.doParse(StreamSourceChannel) method to
| parse large form data encoding with application/x-www-form-
| urlencoded, the method will cause an OutOfMemory issue. This flaw
| allows unauthorized users to cause a remote denial of service (DoS)
| attack.

https://bugzilla.redhat.com/show_bug.cgi?id=2275287


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2024-3884
    https://www.cve.org/CVERecord?id=CVE-2024-3884

Please adjust the affected versions in the BTS as needed.



More information about the pkg-java-maintainers mailing list