Undertow
Security Risk Profile
40
/100
mediumSecurity Risk Score
Comprehensive risk assessment based on 8 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from January 15, 2018 to present
8
Total CVEs
5
Critical+High
0
Exploited
4
Unpatched
Threat Assessment
Avg CVSS
5.7
Base severity
Avg EPSS
1%
Exploit probability
Unpatched
4
Critical/High
Risk Level
40/100
medium
Severity Distribution
Critical
0High
5Medium
2Low
1Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
1Age Distribution
Common Weaknesses (CWE)
1
Input Validation
2
2
Path Traversal
1
Most Affected Products
1. Undertow Undertow8
2. maven/io.undertow:undertow-core2
3. redhat JBoss Enterprise Application Platform2
4. redhat Enterprise Linux2
5. HTTP/2 HTTP/21
Recent Vulnerabilities
See more →CVE-2024-4027
CVSS 7.5high
Undertow: outofmemoryerror in httpservletrequestimpl.getparameternames() can cause remote dos attacks
1/30/2026
CVE-2025-9784
CVSS 7.5EPSS 1%high
Undertow: undertow madeyoureset http/2 ddos vulnerability
9/1/2025🔧 No Patch
REDHAT-BUG-2305290
CVSS 7.0high
8/16/2024🔧 No Patch
REDHAT-BUG-2292211
CVSS 7.0high
6/13/2024🔧 No Patch
CVE-2024-3884
CVSS 7.5high
Undertow: outofmemory when parsing form data encoding with application/x-www-form-urlencoded
4/16/2024🔧 No Patch
REDHAT-BUG-2275287
CVSS 4.0medium
4/16/2024🔧 No Patch
REDHAT-BUG-2274437
CVSS 1.0low
4/11/2024🔧 No Patch
REDHAT-BUG-1534343
CVSS 4.0medium
1/15/2018🔧 No Patch
Monitor Undertow in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.