<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 01:55:18 +0000</lastBuildDate>
    <item>
      <title>certfr-2021-avi-951 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de
RedHat. Certaines d'entre elles permettent à un…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-951</link>
      <description>certfr-2021-avi-951</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-951</guid>
    </item>
    <item>
      <title>EUVD-2026-21033</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-21033</link>
      <description>EUVD-2026-21033</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-21033</guid>
    </item>
    <item>
      <title>fkie_cve-2021-3690</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-3690</link>
      <description>&lt;p&gt;A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is availability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is availability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-3690</guid>
    </item>
    <item>
      <title>GHSA-fj7c-vg2v-ccrm — Undertow vulnerable to memory exhaustion due to buffer leak</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fj7c-vg2v-ccrm</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: io.undertow:undertow-core&lt;/p&gt;
&lt;p&gt;Buffer leak on incoming WebSocket PONG message(s) in Undertow before 2.0.40 and 2.2.10 can lead to memory exhaustion and allow a denial of service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: io.undertow:undertow-core&lt;/p&gt;
&lt;p&gt;Buffer leak on incoming WebSocket PONG message(s) in Undertow before 2.0.40 and 2.2.10 can lead to memory exhaustion and allow a denial of service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fj7c-vg2v-ccrm</guid>
    </item>
    <item>
      <title>gsd-2021-3690</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-3690</link>
      <description>gsd-2021-3690</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-3690</guid>
    </item>
    <item>
      <title>OESA-2024-2353 — undertow security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-2353</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: undertow, openEuler:22.03-LTS-SP3: undertow, openEuler:20.03-LTS-SP4: undertow, openEuler:22.03-LTS-SP1: undertow, openEuler:24.03-LTS: undertow&lt;/p&gt;
&lt;p&gt;Java web server using non-blocking IO&#13;
&#13;
Security Fix(es):&#13;
&#13;
A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is availability.(CVE-2021-3690)&#13;
&#13;
A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error state by mod_cluster in httpd, causing JBoss EAP to close the TCP connection without returning an AJP response. This happens because mod_proxy_cluster marks the JBoss EAP instance as an error worker when the TCP connection is closed from the backend after sending the AJP request without receiving an AJP response, and stops forwarding. This issue could allow a malicious user could to repeatedly send requests that exceed the max-header-size, causing a Denial of Service (DoS).(CVE-2023-5379)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: undertow, openEuler:22.03-LTS-SP3: undertow, openEuler:20.03-LTS-SP4: undertow, openEuler:22.03-LTS-SP1: undertow, openEuler:24.03-LTS: undertow&lt;/p&gt;
&lt;p&gt;Java web server using non-blocking IO&#13;
&#13;
Security Fix(es):&#13;
&#13;
A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is availability.(CVE-2021-3690)&#13;
&#13;
A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error state by mod_cluster in httpd, causing JBoss EAP to close the TCP connection without returning an AJP response. This happens because mod_proxy_cluster marks the JBoss EAP instance as an error worker when the TCP connection is closed from the backend after sending the AJP request without receiving an AJP response, and stops forwarding. This issue could allow a malicious user could to repeatedly send requests that exceed the max-header-size, causing a Denial of Service (DoS).(CVE-2023-5379)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-2353</guid>
    </item>
    <item>
      <title>RHSA-2021:3216 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:3216</link>
      <description>&lt;p&gt;undertow: buffer leak on incoming websocket PONG message may lead to DoS&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;undertow: buffer leak on incoming websocket PONG message may lead to DoS&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:3216</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-3690</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3690</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: undertow, Ubuntu:Pro:18.04:LTS: undertow, Ubuntu:Pro:20.04:LTS: undertow, Ubuntu:Pro:22.04:LTS: undertow, Ubuntu:Pro:24.04:LTS: undertow, Ubuntu:25.10: undertow, Ubuntu:26.04:LTS: undertow&lt;/p&gt;
&lt;p&gt;A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is availability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: undertow, Ubuntu:Pro:18.04:LTS: undertow, Ubuntu:Pro:20.04:LTS: undertow, Ubuntu:Pro:22.04:LTS: undertow, Ubuntu:Pro:24.04:LTS: undertow, Ubuntu:25.10: undertow, Ubuntu:26.04:LTS: undertow&lt;/p&gt;
&lt;p&gt;A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is availability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3690</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0916 — Red Hat JBoss Enterprise Application Platform: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0916</link>
      <description>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in der Red Hat JBoss Enterprise Application Platform ausnutzen, um Sicherheitsvorkehrungen zu umgehen, einen Denial of Service Zustand auszulösen und vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in der Red Hat JBoss Enterprise Application Platform ausnutzen, um Sicherheitsvorkehrungen zu umgehen, einen Denial of Service Zustand auszulösen und vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0916</guid>
    </item>
  </channel>
</rss>
