{
  "threat_severity" : "Moderate",
  "public_date" : "2025-12-03T16:50:50Z",
  "bugzilla" : {
    "description" : "undertow: OutOfMemory when parsing form data encoding with application/x-www-form-urlencoded",
    "id" : "2275287",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2275287"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-20",
  "details" : [ "A flaw was found in Undertow that can cause remote denial of service attacks. When the server uses the FormEncodedDataDefinition.doParse(StreamSourceChannel) method to parse large form data encoding with application/x-www-form-urlencoded, the method will cause an OutOfMemory issue. This flaw allows unauthorized users to cause a remote denial of service (DoS) attack.", "A flaw was found in Undertow that can cause remote denial of service attacks. When the server uses the FormEncodedDataDefinition.doParse(StreamSourceChannel) method to parse large form data encoding with application/x-www-form-urlencoded, the method will cause an OutOfMemory issue. This flaw allows unauthorized users to cause a remote denial of service (DoS) attack." ],
  "statement" : "Red Hat rates this as a Moderate impact since this requires the use of a specific form method by the server that must be externally available and the input is not sanitized by the given servlet or class implementing its use.",
  "affected_release" : [ {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7",
    "release_date" : "2026-03-30T00:00:00Z",
    "advisory" : "RHSA-2026:6012",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7",
    "package" : "eap7-undertow-0:1.4.18-19.SP17_redhat_00001.1.ep7.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7",
    "release_date" : "2026-03-30T00:00:00Z",
    "advisory" : "RHSA-2026:6012",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7",
    "package" : "eap7-wildfly-0:7.1.14-4.GA_redhat_00003.1.ep7.el7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7",
    "release_date" : "2026-03-30T00:00:00Z",
    "advisory" : "RHSA-2026:6011",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.3::el7",
    "package" : "eap7-undertow-0:2.0.41-7.SP8_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7",
    "release_date" : "2026-03-30T00:00:00Z",
    "advisory" : "RHSA-2026:6011",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.3::el7",
    "package" : "eap7-wildfly-0:7.3.17-5.GA_redhat_00006.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.4",
    "release_date" : "2026-03-18T00:00:00Z",
    "advisory" : "RHSA-2026:4924",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7.4",
    "package" : "undertow"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7",
    "release_date" : "2026-03-18T00:00:00Z",
    "advisory" : "RHSA-2026:4915",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform_els:7.4::el7",
    "package" : "eap7-undertow-0:2.2.39-1.Final_redhat_00001.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7",
    "release_date" : "2026-03-18T00:00:00Z",
    "advisory" : "RHSA-2026:4915",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform_els:7.4::el7",
    "package" : "eap7-wildfly-0:7.4.24-4.GA_redhat_00002.1.el7eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8",
    "release_date" : "2026-03-18T00:00:00Z",
    "advisory" : "RHSA-2026:4916",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform_els:7.4::el8",
    "package" : "eap7-undertow-0:2.2.39-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8",
    "release_date" : "2026-03-18T00:00:00Z",
    "advisory" : "RHSA-2026:4916",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform_els:7.4::el8",
    "package" : "eap7-wildfly-0:7.4.24-4.GA_redhat_00002.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9",
    "release_date" : "2026-03-18T00:00:00Z",
    "advisory" : "RHSA-2026:4917",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform_els:7.4::el9",
    "package" : "eap7-undertow-0:2.2.39-1.Final_redhat_00001.1.el9eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9",
    "release_date" : "2026-03-18T00:00:00Z",
    "advisory" : "RHSA-2026:4917",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform_els:7.4::el9",
    "package" : "eap7-wildfly-0:7.4.24-4.GA_redhat_00002.1.el9eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.0",
    "release_date" : "2026-03-05T00:00:00Z",
    "advisory" : "RHSA-2026:3892",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el8",
    "package" : "undertow"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8",
    "release_date" : "2026-03-05T00:00:00Z",
    "advisory" : "RHSA-2026:3889",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el8",
    "package" : "eap8-bouncycastle-0:1.83.0-1.redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8",
    "release_date" : "2026-03-05T00:00:00Z",
    "advisory" : "RHSA-2026:3889",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el8",
    "package" : "eap8-guava-libraries-0:33.0.0-2.jre_redhat_00003.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8",
    "release_date" : "2026-03-05T00:00:00Z",
    "advisory" : "RHSA-2026:3889",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el8",
    "package" : "eap8-jaxb-0:4.0.6-1.redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8",
    "release_date" : "2026-03-05T00:00:00Z",
    "advisory" : "RHSA-2026:3889",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el8",
    "package" : "eap8-jcip-annotations-0:1.0.0-3.redhat_00009.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8",
    "release_date" : "2026-03-05T00:00:00Z",
    "advisory" : "RHSA-2026:3889",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el8",
    "package" : "eap8-slf4j-jboss-logmanager-0:2.0.2-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8",
    "release_date" : "2026-03-05T00:00:00Z",
    "advisory" : "RHSA-2026:3889",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el8",
    "package" : "eap8-undertow-0:2.3.23-1.SP3_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9",
    "release_date" : "2026-03-05T00:00:00Z",
    "advisory" : "RHSA-2026:3891",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el9",
    "package" : "eap8-bouncycastle-0:1.83.0-1.redhat_00001.1.el9eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9",
    "release_date" : "2026-03-05T00:00:00Z",
    "advisory" : "RHSA-2026:3891",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el9",
    "package" : "eap8-guava-libraries-0:33.0.0-2.jre_redhat_00003.1.el9eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9",
    "release_date" : "2026-03-05T00:00:00Z",
    "advisory" : "RHSA-2026:3891",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el9",
    "package" : "eap8-jaxb-0:4.0.6-1.redhat_00001.1.el9eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9",
    "release_date" : "2026-03-05T00:00:00Z",
    "advisory" : "RHSA-2026:3891",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el9",
    "package" : "eap8-jcip-annotations-0:1.0.0-3.redhat_00009.1.el9eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9",
    "release_date" : "2026-03-05T00:00:00Z",
    "advisory" : "RHSA-2026:3891",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el9",
    "package" : "eap8-slf4j-jboss-logmanager-0:2.0.2-1.Final_redhat_00001.1.el9eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9",
    "release_date" : "2026-03-05T00:00:00Z",
    "advisory" : "RHSA-2026:3891",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el9",
    "package" : "eap8-undertow-0:2.3.23-1.SP3_redhat_00001.1.el9eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0386",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el8",
    "package" : "undertow"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0383",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el8",
    "package" : "eap8-apache-cxf-0:4.0.10-1.redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0383",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el8",
    "package" : "eap8-bouncycastle-0:1.82.0-1.redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0383",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el8",
    "package" : "eap8-eap-product-conf-parent-0:801.3.0-1.GA_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0383",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el8",
    "package" : "eap8-eventstream-0:1.0.1-3.redhat_00003.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0383",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el8",
    "package" : "eap8-hibernate-0:6.6.36-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0383",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el8",
    "package" : "eap8-jboss-el-api_5.0_spec-0:4.0.2-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0383",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el8",
    "package" : "eap8-jboss-threads-0:2.5.0-1.redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0383",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el8",
    "package" : "eap8-undertow-0:2.3.20-2.SP4_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0383",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el8",
    "package" : "eap8-wildfly-0:8.1.3-4.GA_redhat_00006.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0383",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el8",
    "package" : "eap8-wildfly-clustering-0:5.0.12-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0383",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el8",
    "package" : "eap8-wildfly-elytron-0:2.6.6-1.Final_redhat_00001.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0383",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el8",
    "package" : "eap8-wildfly-javadocs-0:8.1.1-4.GA_redhat_00007.1.el8eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0384",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el9",
    "package" : "eap8-apache-cxf-0:4.0.10-1.redhat_00001.1.el9eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0384",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el9",
    "package" : "eap8-bouncycastle-0:1.82.0-1.redhat_00001.1.el9eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0384",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el9",
    "package" : "eap8-eap-product-conf-parent-0:801.3.0-1.GA_redhat_00001.1.el9eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0384",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el9",
    "package" : "eap8-eventstream-0:1.0.1-3.redhat_00003.1.el9eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0384",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el9",
    "package" : "eap8-hibernate-0:6.6.36-1.Final_redhat_00001.1.el9eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0384",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el9",
    "package" : "eap8-jboss-el-api_5.0_spec-0:4.0.2-1.Final_redhat_00001.1.el9eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0384",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el9",
    "package" : "eap8-jboss-threads-0:2.5.0-1.redhat_00001.1.el9eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0384",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el9",
    "package" : "eap8-undertow-0:2.3.20-2.SP4_redhat_00001.1.el9eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0384",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el9",
    "package" : "eap8-wildfly-0:8.1.3-4.GA_redhat_00006.1.el9eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0384",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el9",
    "package" : "eap8-wildfly-clustering-0:5.0.12-1.Final_redhat_00001.1.el9eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0384",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el9",
    "package" : "eap8-wildfly-elytron-0:2.6.6-1.Final_redhat_00001.1.el9eap"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9",
    "release_date" : "2026-01-08T00:00:00Z",
    "advisory" : "RHSA-2026:0384",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el9",
    "package" : "eap8-wildfly-javadocs-0:8.1.1-4.GA_redhat_00007.1.el9eap"
  } ],
  "package_state" : [ {
    "product_name" : "OpenShift Serverless",
    "fix_state" : "Under investigation",
    "package_name" : "undertow",
    "cpe" : "cpe:/a:redhat:serverless:1"
  }, {
    "product_name" : "Red Hat build of Apache Camel 4 for Quarkus 3",
    "fix_state" : "Under investigation",
    "package_name" : "undertow",
    "cpe" : "cpe:/a:redhat:camel_quarkus:3"
  }, {
    "product_name" : "Red Hat build of Apache Camel for Spring Boot 3",
    "fix_state" : "Under investigation",
    "package_name" : "undertow",
    "cpe" : "cpe:/a:redhat:camel_spring_boot:3"
  }, {
    "product_name" : "Red Hat build of Apache Camel for Spring Boot 4",
    "fix_state" : "Under investigation",
    "package_name" : "undertow",
    "cpe" : "cpe:/a:redhat:camel_spring_boot:4"
  }, {
    "product_name" : "Red Hat build of Apache Camel - HawtIO 4",
    "fix_state" : "Under investigation",
    "package_name" : "undertow",
    "cpe" : "cpe:/a:redhat:apache_camel_hawtio:4"
  }, {
    "product_name" : "Red Hat build of Apicurio Registry 2",
    "fix_state" : "Under investigation",
    "package_name" : "undertow",
    "cpe" : "cpe:/a:redhat:service_registry:2"
  }, {
    "product_name" : "Red Hat Build of Keycloak",
    "fix_state" : "Under investigation",
    "package_name" : "undertow",
    "cpe" : "cpe:/a:redhat:build_keycloak:"
  }, {
    "product_name" : "Red Hat build of OptaPlanner 8",
    "fix_state" : "Under investigation",
    "package_name" : "undertow",
    "cpe" : "cpe:/a:redhat:optaplanner:::el6"
  }, {
    "product_name" : "Red Hat build of Quarkus",
    "fix_state" : "Under investigation",
    "package_name" : "io.quarkus/quarkus-undertow",
    "cpe" : "cpe:/a:redhat:quarkus:2"
  }, {
    "product_name" : "Red Hat build of Quarkus",
    "fix_state" : "Under investigation",
    "package_name" : "io.quarkus/quarkus-undertow",
    "cpe" : "cpe:/a:redhat:quarkus:3"
  }, {
    "product_name" : "Red Hat Data Grid 8",
    "fix_state" : "Under investigation",
    "package_name" : "undertow",
    "cpe" : "cpe:/a:redhat:jboss_data_grid:8"
  }, {
    "product_name" : "Red Hat Fuse 7",
    "fix_state" : "Out of support scope",
    "package_name" : "undertow",
    "cpe" : "cpe:/a:redhat:jboss_fuse:7"
  }, {
    "product_name" : "Red Hat Integration Camel K 1",
    "fix_state" : "Under investigation",
    "package_name" : "undertow",
    "cpe" : "cpe:/a:redhat:integration:1"
  }, {
    "product_name" : "Red Hat Integration Camel Quarkus 2",
    "fix_state" : "Under investigation",
    "package_name" : "undertow",
    "cpe" : "cpe:/a:redhat:camel_quarkus:2"
  }, {
    "product_name" : "Red Hat JBoss Data Grid 7",
    "fix_state" : "Out of support scope",
    "package_name" : "undertow",
    "cpe" : "cpe:/a:redhat:jboss_data_grid:7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform Expansion Pack",
    "fix_state" : "Not affected",
    "package_name" : "undertow",
    "cpe" : "cpe:/a:redhat:jbosseapxp"
  }, {
    "product_name" : "Red Hat JBoss Fuse Service Works 6",
    "fix_state" : "Out of support scope",
    "package_name" : "undertow",
    "cpe" : "cpe:/a:redhat:jboss_fuse_service_works:6"
  }, {
    "product_name" : "Red Hat Process Automation 7",
    "fix_state" : "Out of support scope",
    "package_name" : "undertow",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_bpms_platform:7"
  }, {
    "product_name" : "Red Hat Single Sign-On 7",
    "fix_state" : "Under investigation",
    "package_name" : "undertow",
    "cpe" : "cpe:/a:redhat:red_hat_single_sign_on:7"
  }, {
    "product_name" : "streams for Apache Kafka",
    "fix_state" : "Under investigation",
    "package_name" : "undertow",
    "cpe" : "cpe:/a:redhat:amq_streams:1"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2024-3884\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-3884" ],
  "name" : "CVE-2024-3884",
  "mitigation" : {
    "value" : "It is possible to mitigate the vulnerability by performing an upper-level verification to ensure the content size sent server side is within the allowed parameters.",
    "lang" : "en:us"
  },
  "csaw" : false
}