CVE-2021-3690
Undertow vulnerable to memory exhaustion due to buffer leak
Description
Buffer leak on incoming WebSocket PONG message(s) in Undertow before 2.0.40 and 2.2.10 can lead to memory exhaustion and allow a denial of service.
Base CVSS
7.5
EPSS Score
0.52%
Introduced Version
1.0.0.Beta2
Fix Available
2.2.10.Final,2.0.40.Final
Available Patches
Package
CVEs Fixed
Lines of Code Changed