CVE-2024-3884
mediumEPSS Score
1.4%
Exploitation probability in 30 days
Top 30% most likely to be exploited
Published: December 3, 2025 (278 days ago)
Last Modified: August 19, 2026
Vendor: Apache
Source: MITRE
Vulnerability Report
Generated by CyberWatcher
Description
A flaw was found in Undertow that can cause remote denial of service attacks. When the server uses the FormEncodedDataDefinition.doParse(StreamSourceChannel) method to parse large form data encoding with application/x-www-form-urlencoded, the method will cause an OutOfMemory issue. This flaw allows unauthorized users to cause a remote denial of service (DoS) attack.
CWE
CWE-20Affected Products
Red Hat Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7Red Hat Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7Red Hat Red Hat JBoss Enterprise Application Platform 7.4.24Red Hat Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7Red Hat Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8Red Hat Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9Red Hat Red Hat JBoss Enterprise Application Platform 8.0Red Hat Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8Red Hat Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9Red Hat Red Hat JBoss Enterprise Application Platform 8.1