Hi,
The following vulnerability was published for undertow.
CVE-2024-3884[0]:
| A flaw was found in Undertow that can cause remote denial of service
| attacks. When the server uses the
| FormEncodedDataDefinition.doParse(StreamSourceChannel) method to
| parse large form data encoding with application/x-www-form-
| urlencoded, the method will cause an OutOfMemory issue. This flaw
| allows unauthorized users to cause a remote denial of service (DoS)
| attack.
https://bugzilla.redhat.com/show_bug.cgi?id=2275287
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2024-3884
https://www.cve.org/CVERecord?id=CVE-2024-3884
Please adjust the affected versions in the BTS as needed.