pkg:Maven/io.undertow:undertow-core
39 total CVEsCRITICAL4HIGH21MEDIUM13
✅ Check your installed version
All known vulnerabilities
- CRITICAL9.8CVE-2022-4492Undertow client not checking server identity presented by server certificate in https connections>= 2.3.0, < 2.3.5.Final
- CRITICAL9.8CVE-2019-10212Potential to access user credentials from the log files when debug logging enabledfrom 0, < 2.0.20
- from 0, < 2.0.21
- CRITICAL9.6CVE-2025-12543Undertow HTTP server core doesn't properly validate the Host header in incoming HTTP requests
- from 0, < 2.0.30
- from 0, < 2.1.0
- HIGH7.5CVE-2024-4027Undertow Servlets Vulnerable to Remote DoS via OutOfMemoryError when Passed Large Parameter Namesfrom 0, < 2.2.39.Final
- HIGH7.5CVE-2024-3884Undertow OutOfMemory when parsing form data encoding with application/x-www-form-urlencodedfrom 0, < 2.2.39.Final
- from 0, < 2.2.38.Final
- from 0, < 2.2.32.Final
- from 0, < 2.2.36.Final
- >= 2.3.0.Alpha1, < 2.3.15.Final
- >= 2.3.0.Alpha1, < 2.3.14.Final
- >= 2.3.0.Final, < 2.3.12.Final
- >= 2.3.0, < 2.3.5.Final
- from 0, < 2.2.19.Final
- from 0, < 2.2.15
- from 0, < 2.0.40
- from 0, < 2.0.40.Final
- from 0, < 2.0.29.Final
- from 0, < 1.3.31
- >= 2.1.0, < 2.1.5
- from 0, < 2.1.1.Final
- from 0, < 1.3.28
- >= 2.3.0.Alpha1, < 2.3.11.Final
- from 0, < 1.4.25.Final
- from 0, < 2.1.1.Final
- from 0, < 1.3.31
- >= 1.4.0, < 1.4.17.Final
- MEDIUM5.9CVE-2026-3260Undertow: Denial of Service via Multipart/Form-Data Parsing on HTTP GET Requestsfrom 0, < 2.4.0.Beta1
- >= 2.1.0, < 2.2.9.Final
- >= 1.4.0, < 1.4.3.Final
- >= 2.0.0.Alpha1, < 2.0.2.FInal
- >= 2.3.0.Alpha1, < 2.3.15.Final
- from 0, < 2.2.31.Final
- from 0, < 2.0.19.FINAL
- >= 2.1.0, < 2.1.6
- from 0, < 2.2.0.Final
- >= 1.0.0, < 1.0.17