<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 11:21:57 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-344259</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-344259</link>
      <description>EUVD-2026-344259</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-344259</guid>
    </item>
    <item>
      <title>fkie_cve-2023-5379</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-5379</link>
      <description>&lt;p&gt;A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error state by mod_cluster in httpd, causing JBoss EAP to close the TCP connection without returning an AJP response. This happens because mod_proxy_cluster marks the JBoss EAP instance as an error worker when the TCP connection is closed from the backend after sending the AJP request without receiving an AJP response, and stops forwarding. This issue could allow a malicious user could to repeatedly send requests that exceed the max-header-size, causing a Denial of Service (DoS).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error state by mod_cluster in httpd, causing JBoss EAP to close the TCP connection without returning an AJP response. This happens because mod_proxy_cluster marks the JBoss EAP instance as an error worker when the TCP connection is closed from the backend after sending the AJP request without receiving an AJP response, and stops forwarding. This issue could allow a malicious user could to repeatedly send requests that exceed the max-header-size, causing a Denial of Service (DoS).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-5379</guid>
    </item>
    <item>
      <title>GHSA-q462-4hrv-w27r</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-q462-4hrv-w27r</link>
      <description>&lt;p&gt;A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error state by mod_cluster in httpd, causing JBoss EAP to close the TCP connection without returning an AJP response. This happens because mod_proxy_cluster marks the JBoss EAP instance as an error worker when the TCP connection is closed from the backend after sending the AJP request without receiving an AJP response, and stops forwarding. This issue could allow a malicious user could to repeatedly send requests that exceed the max-header-size, causing a Denial of Service (DoS).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error state by mod_cluster in httpd, causing JBoss EAP to close the TCP connection without returning an AJP response. This happens because mod_proxy_cluster marks the JBoss EAP instance as an error worker when the TCP connection is closed from the backend after sending the AJP request without receiving an AJP response, and stops forwarding. This issue could allow a malicious user could to repeatedly send requests that exceed the max-header-size, causing a Denial of Service (DoS).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-q462-4hrv-w27r</guid>
    </item>
    <item>
      <title>gsd-2023-5379</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-5379</link>
      <description>gsd-2023-5379</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-5379</guid>
    </item>
    <item>
      <title>OESA-2024-2353 — undertow security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-2353</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: undertow, openEuler:22.03-LTS-SP3: undertow, openEuler:20.03-LTS-SP4: undertow, openEuler:22.03-LTS-SP1: undertow, openEuler:24.03-LTS: undertow&lt;/p&gt;
&lt;p&gt;Java web server using non-blocking IO&#13;
&#13;
Security Fix(es):&#13;
&#13;
A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is availability.(CVE-2021-3690)&#13;
&#13;
A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error state by mod_cluster in httpd, causing JBoss EAP to close the TCP connection without returning an AJP response. This happens because mod_proxy_cluster marks the JBoss EAP instance as an error worker when the TCP connection is closed from the backend after sending the AJP request without receiving an AJP response, and stops forwarding. This issue could allow a malicious user could to repeatedly send requests that exceed the max-header-size, causing a Denial of Service (DoS).(CVE-2023-5379)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: undertow, openEuler:22.03-LTS-SP3: undertow, openEuler:20.03-LTS-SP4: undertow, openEuler:22.03-LTS-SP1: undertow, openEuler:24.03-LTS: undertow&lt;/p&gt;
&lt;p&gt;Java web server using non-blocking IO&#13;
&#13;
Security Fix(es):&#13;
&#13;
A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is availability.(CVE-2021-3690)&#13;
&#13;
A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error state by mod_cluster in httpd, causing JBoss EAP to close the TCP connection without returning an AJP response. This happens because mod_proxy_cluster marks the JBoss EAP instance as an error worker when the TCP connection is closed from the backend after sending the AJP request without receiving an AJP response, and stops forwarding. This issue could allow a malicious user could to repeatedly send requests that exceed the max-header-size, causing a Denial of Service (DoS).(CVE-2023-5379)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-2353</guid>
    </item>
    <item>
      <title>RHSA-2025:9582 — Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.1.11 on RHEL 7 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:9582</link>
      <description>&lt;p&gt;wildfly: unsafe deserialization in Wildfly Enterprise Java Beans libthrift: potential DoS when processing untrusted payloads hibernate-core: SQL injection vulnerability when both hibernate.use_sql_comments and JPQL String literals are used wildfly-openssl: memory leak per HTTP session creation in WildFly OpenSSL undertow: special character in query results in server errors jackson-databind: denial of service via a large depth of nested objects jakarta-el: ELParserTokenManager enables invalid EL expressions to be evaluate netty-codec: Bzip2Decoder doesn&amp;#39;t allow setting size restrictions for decompressed data netty-codec: SnappyFrameDecoder doesn&amp;#39;t restrict chunk length and may buffer skippable chunks in an unnecessary way undertow: potential security issue in flow control over HTTP/2 may lead to DOS(incomplete fix for CVE-2021-3629) wildfly-elytron: possible timing attacks via use of unsafe comparator undertow: Server identity in https connection is not checked by the undertow client undertow: AJP Request closes connection exceeding maxRequestSize EAP: wildfly-elytron has a SSRF security issue&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;wildfly: unsafe deserialization in Wildfly Enterprise Java Beans libthrift: potential DoS when processing untrusted payloads hibernate-core: SQL injection vulnerability when both hibernate.use_sql_comments and JPQL String literals are used wildfly-openssl: memory leak per HTTP session creation in WildFly OpenSSL undertow: special character in query results in server errors jackson-databind: denial of service via a large depth of nested objects jakarta-el: ELParserTokenManager enables invalid EL expressions to be evaluate netty-codec: Bzip2Decoder doesn&amp;#39;t allow setting size restrictions for decompressed data netty-codec: SnappyFrameDecoder doesn&amp;#39;t restrict chunk length and may buffer skippable chunks in an unnecessary way undertow: potential security issue in flow control over HTTP/2 may lead to DOS(incomplete fix for CVE-2021-3629) wildfly-elytron: possible timing attacks via use of unsafe comparator undertow: Server identity in https connection is not checked by the undertow client undertow: AJP Request closes connection exceeding maxRequestSize EAP: wildfly-elytron has a SSRF security issue&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:9582</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-5379</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-5379</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: undertow, Ubuntu:Pro:18.04:LTS: undertow, Ubuntu:Pro:20.04:LTS: undertow, Ubuntu:Pro:22.04:LTS: undertow, Ubuntu:Pro:24.04:LTS: undertow, Ubuntu:25.10: undertow, Ubuntu:26.04:LTS: undertow&lt;/p&gt;
&lt;p&gt;A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error state by mod_cluster in httpd, causing JBoss EAP to close the TCP connection without returning an AJP response. This happens because mod_proxy_cluster marks the JBoss EAP instance as an error worker when the TCP connection is closed from the backend after sending the AJP request without receiving an AJP response, and stops forwarding. This issue could allow a malicious user could to repeatedly send requests that exceed the max-header-size, causing a Denial of Service (DoS).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: undertow, Ubuntu:Pro:18.04:LTS: undertow, Ubuntu:Pro:20.04:LTS: undertow, Ubuntu:Pro:22.04:LTS: undertow, Ubuntu:Pro:24.04:LTS: undertow, Ubuntu:25.10: undertow, Ubuntu:26.04:LTS: undertow&lt;/p&gt;
&lt;p&gt;A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error state by mod_cluster in httpd, causing JBoss EAP to close the TCP connection without returning an AJP response. This happens because mod_proxy_cluster marks the JBoss EAP instance as an error worker when the TCP connection is closed from the backend after sending the AJP request without receiving an AJP response, and stops forwarding. This issue could allow a malicious user could to repeatedly send requests that exceed the max-header-size, causing a Denial of Service (DoS).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-5379</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1203 — NetApp ActiveIQ Unified Manager: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1203</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in NetApp ActiveIQ Unified Manager ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in NetApp ActiveIQ Unified Manager ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1203</guid>
    </item>
  </channel>
</rss>
