HIGH 7.5 Maven

Undertow vulnerable to memory exhaustion due to buffer leak

GHSA-fj7c-vg2v-ccrm · CVE-2021-3690

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Buffer leak on incoming WebSocket PONG message(s) in Undertow before 2.0.40 and 2.2.10 can lead to memory exhaustion and allow a denial of service.

Ready to move

Start Securing

Free, no credit card | First findings in minutes