OESA-2026-1386

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-1386
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-1386.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-1386
Upstream
  • CVE-2024-3884
  • CVE-2024-4027
Published
2026-02-13T11:10:24Z
Modified
2026-08-18T01:19:40Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
undertow security update
Details

Java web server using non-blocking IO

Security Fix(es):

A flaw was found in Undertow that can cause remote denial of service attacks. When the server uses the FormEncodedDataDefinition.doParse(StreamSourceChannel) method to parse large form data encoding with application/x-www-form-urlencoded, the method will cause an OutOfMemory issue. This flaw allows unauthorized users to cause a remote denial of service (DoS) attack.(CVE-2024-3884)

A flaw was found in Undertow. Servlets using a method that calls HttpServletRequestImpl.getParameterNames() can cause an OutOfMemoryError when the client sends a request with large parameter names. This issue can be exploited by an unauthorized user to cause a remote denial-of-service (DoS) attack.(CVE-2024-4027)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:22.03-LTS-SP4 / undertow

Package

Name
undertow
Purl
pkg:rpm/openEuler/undertow&distro=openEuler-22.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.4.0-10.oe2203sp4

Ecosystem specific

{
    "noarch": [
        "undertow-1.4.0-10.oe2203sp4.noarch.rpm",
        "undertow-javadoc-1.4.0-10.oe2203sp4.noarch.rpm"
    ],
    "src": [
        "undertow-1.4.0-10.oe2203sp4.src.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-1386.json"