Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-4027

Опубликовано: 30 янв. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in Undertow. Servlets using a method that calls HttpServletRequestImpl.getParameterNames() can cause an OutOfMemoryError when the client sends a request with large parameter names. This issue can be exploited by an unauthorized user to cause a remote denial-of-service (DoS) attack.

Отчет

Red Hat rates this issue as an important impact since a malicious user may benefit from causing Denial of Service (DoS) to the server by sending large post requests as application/x-www-form-urlencoded or multipart/form-data, causing the parsing to run an OutOfMemoryError.

Меры по смягчению последствий

Currently no mitigation is available for this vulnerability. Please make sure to perform the update as they become available.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift ServerlessundertowUnder investigation
Red Hat build of Apache Camel 4 for Quarkus 3undertowUnder investigation
Red Hat build of Apache Camel for Spring Boot 3undertowUnder investigation
Red Hat build of Apache Camel for Spring Boot 4undertowUnder investigation
Red Hat build of Apache Camel - HawtIO 4undertowUnder investigation
Red Hat build of Apicurio Registry 2undertowAffected
Red Hat Build of KeycloakundertowUnder investigation
Red Hat build of OptaPlanner 8undertowUnder investigation
Red Hat build of Quarkusquarkus-undertowOut of support scope
Red Hat build of Quarkusquarkus-undertowNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=2276410undertow: OutOfMemoryError in HttpServletRequestImpl.getParameterNames() can cause remote DoS attacks

EPSS

Процентиль: 44%
0.00575
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
6 месяцев назад

A flaw was found in Undertow. Servlets using a method that calls HttpServletRequestImpl.getParameterNames() can cause an OutOfMemoryError when the client sends a request with large parameter names. This issue can be exploited by an unauthorized user to cause a remote denial-of-service (DoS) attack.

CVSS3: 7.5
nvd
6 месяцев назад

A flaw was found in Undertow. Servlets using a method that calls HttpServletRequestImpl.getParameterNames() can cause an OutOfMemoryError when the client sends a request with large parameter names. This issue can be exploited by an unauthorized user to cause a remote denial-of-service (DoS) attack.

CVSS3: 7.5
debian
6 месяцев назад

A flaw was found in Undertow. Servlets using a method that calls HttpS ...

CVSS3: 7.5
github
6 месяцев назад

Undertow Servlets Vulnerable to Remote DoS via OutOfMemoryError when Passed Large Parameter Names

EPSS

Процентиль: 44%
0.00575
Низкий

7.5 High

CVSS3