Bug#1123001: undertow: CVE-2024-3884
Moritz Mühlenhoff
jmm at inutil.org
Mon Dec 15 19:13:05 GMT 2025
Source: undertow
X-Debbugs-CC: team at security.debian.org
Severity: important
Tags: security
Hi,
The following vulnerability was published for undertow.
CVE-2024-3884[0]:
| A flaw was found in Undertow that can cause remote denial of service
| attacks. When the server uses the
| FormEncodedDataDefinition.doParse(StreamSourceChannel) method to
| parse large form data encoding with application/x-www-form-
| urlencoded, the method will cause an OutOfMemory issue. This flaw
| allows unauthorized users to cause a remote denial of service (DoS)
| attack.
https://bugzilla.redhat.com/show_bug.cgi?id=2275287
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2024-3884
https://www.cve.org/CVERecord?id=CVE-2024-3884
Please adjust the affected versions in the BTS as needed.
More information about the pkg-java-maintainers
mailing list