Where
-Infinity
0

redhat JBoss Enterprise Application PlatformUndertow: undertow: request smuggling via inconsistent header parsing

Risk 66
Severity
9.1
First published (updated )

redhat JBoss Enterprise Application PlatformUndertow: undertow: request smuggling via `\r\r\r` as a header block terminator

Risk 66
Severity
9.1
First published (updated )

Red Hat UndertowUndertow allows `\r\r\r` as a header block terminator. This can be used for request smuggling with p…

Risk 33
Severity
7
First published (updated )

Red Hat UndertowA vulnerability was identified in Undertow (as used in Wildfly) where the server prematurely parses …

Risk 19
Severity
4
First published (updated )

Red Hat UndertowDescription: Product Security received a report that Undertow might incorrectly re-use an HTTP reque…

Risk 23
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

redhat/eap7-undertowSSRF

Risk 89
Severity
9.8
First published (updated )

redhat/eap7-undertowUndertowInputStream.close() blocks waiting to read -1 https://issues.redhat.com/browse/UNDERTOW-204…

Risk 30
Severity
4.9
First published (updated )

redhat undertowA flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sending two response pack…

Risk 45
Severity
7.5
First published (updated )

redhat/eap7-undertowA flaw was found in Undertow. A potential security issue in flow control handling by the browser ove…

Risk 45
Severity
7.5
First published (updated )

redhat/eap7-undertowInvocation of an EJB is failing on the client side with the invocation-timeout being hit. Reference…

Risk 45
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

redhat/eap7-undertowA vulnerability was found in Undertow where buffer leak on incoming websocket PONG message may lead …

Risk 45
Severity
7.5
First published (updated )

redhat undertowRace Condition

Risk 36
Severity
5.9
First published (updated )

redhat/eap7-activemq-artemisundertow handles certain query string characters improperly. An attacker could use this flaw to send…

Risk 46
Severity
7.8
First published (updated )

Red Hat UndertowIn some circumstances Undertow can serve data from a random ByteBuffer, this is due to an incomplete…

Risk 19
Severity
4
First published (updated )

redhat JBoss Enterprise Application PlatformIt was found in Undertow before 1.3.28 that with non-clean TCP close, the Websocket server gets into…

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Red Hat UndertowIt was found that code that parsed the HTTP request line in undertow permitted invalid characters wh…

Risk 19
Severity
4
First published (updated )

redhat/undertowPath Traversal

Risk 27
Severity
5
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203