Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fhmg-q5fc-2m8v

Опубликовано: 11 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments on the listener, and achieving Denial of Service.

A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments on the listener, and achieving Denial of Service.

EPSS

Процентиль: 28%
0.0035
Низкий

7.5 High

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 7.5
ubuntu
5 дней назад

A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments on the listener, and achieving Denial of Service.

CVSS3: 7.5
redhat
7 дней назад

A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments on the listener, and achieving Denial of Service.

CVSS3: 7.5
nvd
7 дней назад

A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments on the listener, and achieving Denial of Service.

CVSS3: 7.5
debian
7 дней назад

A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. ...

EPSS

Процентиль: 28%
0.0035
Низкий

7.5 High

CVSS3

Дефекты

CWE-770