undertow-io/undertow

undertow-io/undertow

Releases351
Frequency1 week 6 days
Last Release
Stars3.76K
High performance non-blocking webserver

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
all versions7.5 HIGH

A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).

= 2.3.0, = 2.2.19, = 2.2.17, < 2.2.177.5 HIGH

A flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sending two response packets, and those packets have the reuse flag set even though JBoss EAP closes the connection. A failure occurs when the connection is reused after a 400 by CPING since it reads in the second SEND_HEADERS response packet instead of a CPONG.

< 2.2.157.5 HIGH

A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks.

< 2.0.40, >= 2.1.0, < 2.2.107.5 HIGH

A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is availability.

< 2.0.237.5 HIGH5 MEDIUM

undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.