GHSA-339q-62wm-c39w
GitHub Security Advisory
Undertow vulnerable to Denial of Service (DoS) attacks
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Undertow client side invocation timeout raised when calling over HTTP2, this vulnerability can allow attacker to carry out denial of service (DoS) attacks in versions less than 2.2.15 Final.
Affected Packages
Maven
io.undertow:undertow-core
Affected versions:
0
(fixed in 2.2.15)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: August 3, 2025 6:48 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.