A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HNetapp Oncommand Workflow Automation
APPNetappall versionsRed Hat Build Of Quarkus
APPRedhatall versionsRed Hat Decision Manager
APPRedhat7.0Red Hat Enterprise Linux
OSRedhat7.08.09.0Red Hat Fuse
APPRedhat1.0.0Red Hat Integration Camel K
APPRedhatall versionsRed Hat Integration Service Registry
APPRedhatall versionsRed Hat Jboss Enterprise Application Platform
APPRedhat7.4Red Hat Jboss Enterprise Application Platform Expansion Pack
APPRedhatall versionsRed Hat Openshift Application Runtimes
APPRedhatall versionsRed Hat OpenShift Container Platform
APPRedhat4.114.12Red Hat Openshift Container Platform For Linuxone
APPRedhat4.104.9Red Hat Openshift Container Platform For Power
APPRedhat4.104.9Red Hat Openstack Platform
APPRedhat13.0Red Hat Process Automation
APPRedhat7.0Red Hat Single Sign On
APPRedhat7.6Red Hat Undertow
APPRedhat< 2.2.242.3.0 – 2.3.5 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
DoS
References
Related vulnerabilities
CVE-2025-32463CRITICAL9.3⚠ KEVPL ✓same product
Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)
CVE-2021-40438CRITICAL9.0⚠ KEVPL ✓same product
SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego
CVE-2019-7609CRITICAL10.0⚠ KEVPL ✓same product
RCE w Kibana Timelion — wykonanie kodu z uprawnieniami procesu
CVE-2019-1003029CRITICAL9.9⚠ KEVPL ✓same product
Jenkins Script Security Plugin — sandbox bypass umożliwiający RCE
CVE-2019-1003030CRITICAL9.9⚠ KEVPL ✓same product
Jenkins Pipeline Groovy Plugin — bypass sandbox i wykonanie kodu (RCE)