Undertow Uncontrolled Resource Consumption
High severity
GitHub Reviewed
Published
May 25, 2022
to the GitHub Advisory Database
•
Updated Jun 12, 2025
Package
Affected versions
<= 2.0.39.Final
>= 2.1.0, <= 2.2.10.Final
Patched versions
2.0.40.Final
2.2.11.Final
Description
Published by the National Vulnerability Database
May 24, 2022
Published to the GitHub Advisory Database
May 25, 2022
Reviewed
May 25, 2022
Last updated
Jun 12, 2025
A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may potentially cause overhead or a denial of service in the server. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.40.Final and prior to 2.2.11.Final.
References