Loading HuntDB...

GHSA-339q-62wm-c39w

GitHub Security Advisory

Undertow vulnerable to Denial of Service (DoS) attacks

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Undertow client side invocation timeout raised when calling over HTTP2, this vulnerability can allow attacker to carry out denial of service (DoS) attacks in versions less than 2.2.15 Final.

Affected Packages

Maven io.undertow:undertow-core
Affected versions: 0 (fixed in 2.2.15)

Related CVEs

Key Information

GHSA ID
GHSA-339q-62wm-c39w
Published
July 15, 2022 9:32 PM
Last Modified
September 8, 2022 2:24 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
io.undertow:undertow-core
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 3, 2025 6:48 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.