#VU96051 Resource exhaustion in Undertow - CVE-2024-3653
Published: August 15, 2024
Undertow
Red Hat Inc.
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to incorrect handling of requests within the LearningPushHandler. A remote attacker can send specially crafted requests to the web server and consume available memory, leading to a denial of service.
Successful exploitation of the vulnerability requires that the learning-push handler is enabled (disabled by default).