OESA-2026-1388

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-1388
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-1388.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-1388
Upstream
  • CVE-2024-3884
  • CVE-2024-4027
Published
2026-02-13T11:10:24Z
Modified
2026-08-18T01:19:39Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
undertow security update
Details

Java web server using non-blocking IO

Security Fix(es):

A flaw was found in Undertow that can cause remote denial of service attacks. When the server uses the FormEncodedDataDefinition.doParse(StreamSourceChannel) method to parse large form data encoding with application/x-www-form-urlencoded, the method will cause an OutOfMemory issue. This flaw allows unauthorized users to cause a remote denial of service (DoS) attack.(CVE-2024-3884)

A flaw was found in Undertow. Servlets using a method that calls HttpServletRequestImpl.getParameterNames() can cause an OutOfMemoryError when the client sends a request with large parameter names. This issue can be exploited by an unauthorized user to cause a remote denial-of-service (DoS) attack.(CVE-2024-4027)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:24.03-LTS-SP1 / undertow

Package

Name
undertow
Purl
pkg:rpm/openEuler/undertow&distro=openEuler-24.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.4.0-11.oe2403sp1

Ecosystem specific

{
    "noarch": [
        "undertow-1.4.0-11.oe2403sp1.noarch.rpm",
        "undertow-javadoc-1.4.0-11.oe2403sp1.noarch.rpm"
    ],
    "src": [
        "undertow-1.4.0-11.oe2403sp1.src.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-1388.json"