Remote Code Execution Vulnerability in Undertow by Red Hat
CVE-2026-3260

5.9MEDIUM

What is CVE-2026-3260?

A security flaw in Undertow allows remote attackers to exploit the server by sending an HTTP GET request with multipart/form-data content. When the application processes these parameters using methods such as getParameterMap(), it can lead to premature parsing and unauthorized storage of data on disk. This action can induce resource exhaustion, ultimately causing Denial of Service (DoS) situations, affecting system reliability and availability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.