Loading HuntDB...

GHSA-rhcw-wjcm-9h6g

GitHub Security Advisory

Denial of service in Undertow

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes could be triggered by an attacker using query strings with non-RFC compliant characters resulting in a denial of service. The highest threat from this vulnerability is to system availability. This affects Undertow 2.1.5.SP1, 2.0.33.SP2, and 2.2.3.SP1.

Affected Packages

Maven io.undertow:undertow-core
Affected versions: 2.1.0 (fixed in 2.1.5)
Maven io.undertow:undertow-core
Affected versions: 0 (fixed in 2.0.33)

Related CVEs

Key Information

GHSA ID
GHSA-rhcw-wjcm-9h6g
Published
February 9, 2022 12:54 AM
Last Modified
March 31, 2021 11:48 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
io.undertow:undertow-core
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 3, 2025 6:48 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.