Skip to content

[GHSA-3x3v-w654-m28m] Undertow: Denial of Service via Multipart/Form-Data Parsing on HTTP GET Requests#7796

Open
julianladisch wants to merge 1 commit into
julianladisch/advisory-improvement-7796from
julianladisch-GHSA-3x3v-w654-m28m
Open

[GHSA-3x3v-w654-m28m] Undertow: Denial of Service via Multipart/Form-Data Parsing on HTTP GET Requests#7796
julianladisch wants to merge 1 commit into
julianladisch/advisory-improvement-7796from
julianladisch-GHSA-3x3v-w654-m28m

Conversation

@julianladisch
Copy link
Copy Markdown

Updates

  • Affected products
  • References

Comments
There isn't any indication that the issue got fixed.

Red Hat reports: "Fix deferred": https://access.redhat.com/security/cve/CVE-2026-3260

Release page doesn't mention CVE-2026-3260: https://github.com/undertow-io/undertow/releases

undertow.io doesn't mention CVE-2026-3260 at all: https://github.com/search?q=org%3Aundertow-io+CVE-2026-3260&type=code

@github-actions github-actions Bot changed the base branch from main to julianladisch/advisory-improvement-7796 May 22, 2026 10:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant