Dependency scanning
Check whether io.undertow:undertow-core is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2024-4109
Withdrawn Advisory: undertow: information leakage via HTTP/2 request header reuse
CVE-2026-3260
Undertow: Denial of Service via Multipart/Form-Data Parsing on HTTP GET Requests
CVE-2025-12543
Undertow HTTP server core doesn't properly validate the Host header in incoming HTTP requests
CVE-2024-3884
Undertow OutOfMemory when parsing form data encoding with application/x-www-form-urlencoded
CVE-2025-9784
Undertow MadeYouReset HTTP/2 DDoS Vulnerability
CVE-2023-1108
Undertow denial of service vulnerability
CVE-2024-6162
Undertow's url-encoded request path information can be broken on ajp-listener
CVE-2024-4027
Undertow Servlets Vulnerable to Remote DoS via OutOfMemoryError when Passed Large Parameter Names
CVE-2024-7885
Undertow vulnerable to Race Condition
CVE-2021-3629
Undertow Uncontrolled Resource Consumption
CVE-2024-1635
Undertow Uncontrolled Resource Consumption Vulnerability
CVE-2022-4492
Undertow client not checking server identity presented by server certificate in https connections
CVE-2023-4639
Undertow incorrectly parses cookies
CVE-2014-7816
Improper Limitation of a Pathname to a Restricted Directory in JBoss Undertow
CVE-2024-1459
Undertow Path Traversal vulnerability
CVE-2023-1973
Undertow Denial of Service vulnerability
CVE-2024-3653
Undertow Missing Release of Memory after Effective Lifetime vulnerability
CVE-2024-5971
Undertow Denial of Service vulnerability
CVE-2017-12165
Undertow Request Smuggling vulnerability
CVE-2019-14888
Undertow vulnerable to Uncontrolled Resource Consumption
CVE-2021-3859
Undertow vulnerable to Denial of Service (DoS) attacks
CVE-2020-1745
Improper Authorization in Undertoe
CVE-2020-10705
Allocation of Resources Without Limits or Throttling in Undertow
CVE-2020-10719
HTTP Request Smuggling in Undertow
CVE-2020-10687
HTTP Request Smuggling in Undertow
CVE-2021-20220
HTTP request smuggling in Undertow
CVE-2021-3597
undertow Race Condition vulnerability
CVE-2021-3690
Undertow vulnerable to memory exhaustion due to buffer leak
CVE-2019-3888
Credential exposure through log files in Undertow
CVE-2019-10212
Potential to access user credentials from the log files when debug logging enabled
CVE-2022-2053
Undertow vulnerable to Dos via Large AJP request
CVE-2020-27782
Denial of service in Undertow
CVE-2020-1757
Improper Input Validation in Undertow
CVE-2018-14642
Exposure of Sensitive Information to an Unauthorized Actor in Undertow
CVE-2018-1114
Uncontrolled Resource Consumption in Undertow
CVE-2017-7559
Undertow vulnerable to Request Smuggling
CVE-2017-2670
Moderate severity vulnerability that affects io.undertow:undertow-core
CVE-2017-2666
Undertow-core vulnerable to HTTP Request Smuggling
CVE-2017-12196
Incorrect Authorization in Undertow
CVE-2016-7046
Undertow Uncaught Exception vulnerability
Browse more Maven advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes