#VU101669 Resource management error in Undertow - CVE-2024-4109
Published: December 11, 2024 / Updated: November 24, 2025
Undertow
Red Hat Inc.
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to incorrect handling of HTTP/2 requests when reusing connections, which results in parts of data from previous connection to be included into new responses. A remote attacker can send an HTTP/2 request to the server and gain access to potentially sensitive information.