CVE-2024-3884
A flaw was found in Undertow that can cause remote denial of service attacks. When the server uses the FormEncodedDataDefinition.doParse(StreamSourceChannel) method to parse large form data encoding with application/x-www-form-urlencoded, the method will cause an OutOfMemory issue. This flaw allows unauthorized users to cause a remote denial of service (DoS) attack.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://nvd.nist.gov/vuln/detail/CVE-2024-3884, https://github.com/undertow-io/undertow/pull/1894, https://github.com/undertow-io/undertow/pull/1882, https://github.com/undertow-io/undertow/pull/1860, https://github.com/undertow-io/undertow/pull/1856, https://github.com/undertow-io/undertow/commit/cb854c779b9e2368c3c274ebd7217c8e75d505be, https://github.com/undertow-io/undertow/releases/tag/2.4.0.Beta1, https://github.com/undertow-io/undertow/releases/tag/2.3.21.Final, https://github.com/undertow-io/undertow/releases/tag/2.2.39.Final, https://github.com/undertow-io/undertow, https://bugzilla.redhat.com/show_bug.cgi?id=2275287, https://access.redhat.com/security/cve/CVE-2024-3884, https://access.redhat.com/errata/RHSA-2026:3892, https://access.redhat.com/errata/RHSA-2026:3891, https://access.redhat.com/errata/RHSA-2026:3889, https://access.redhat.com/errata/RHSA-2026:0386, https://access.redhat.com/errata/RHSA-2026:0384, https://access.redhat.com/errata/RHSA-2026:0383, https://access.redhat.com/errata/RHSA-2025:3992, https://access.redhat.com/errata/RHSA-2025:3990, https://access.redhat.com/errata/RHSA-2025:22777, https://access.redhat.com/errata/RHSA-2025:22775, https://access.redhat.com/errata/RHSA-2025:22773
