CVE-2024-4027

All FrameworksJBoss/WildFlyCWE-20CVE-2024-4027

CVE-2024-4027

State: PUBLISHED · Published: 2026-01-30 · Updated: 2026-03-26 · Assigner: redhat
Description
A flaw was found in Undertow. Servlets using a method that calls HttpServletRequestImpl.getParameterNames() can cause an OutOfMemoryError when the client sends a request with large parameter names. This issue can be exploited by an unauthorized user to cause a remote denial-of-service (DoS) attack.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2024/4xxx/CVE-2024-4027.json