A flaw was found in Undertow. A potential security issue in flow control handling by the browser over http/2 may potentially cause overhead or a denial of service in the server. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.40.Final and prior to 2.2.11.Final.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| io.undertow:undertow-core(Maven) | 0 | 2.0.40.Final | N/A |
| io.undertow:undertow-core(Maven) | 2.1.0 | 2.2.11.Final | N/A |
CVSS Metrics