CVE Database
/

CVE-2016-9589

Back to search

CVE-2016-9589

Published: Mar 12, 2018

Modified: Aug 6, 2024

PUBLISHED

Description

Undertow in Red Hat wildfly before version 11.0.0.Beta1 is vulnerable to a resource exhaustion resulting in a denial of service. Undertow keeps a cache of seen HTTP headers in persistent connections. It was found that this cache can easily exploited to fill memory with garbage, up to "max-headers" (default 200) * "max-header-size" (default 1MB) per active TCP connection.

VendorProductVersions

Red Hat, Inc.

wildfly

affected
11.0.0.Beta1

Weaknesses (CWE)

References

RHSA-2017:0831
vendor-advisory
x_refsource_REDHAT
RHSA-2017:0876
vendor-advisory
x_refsource_REDHAT
RHSA-2017:0834
vendor-advisory
x_refsource_REDHAT
RHSA-2017:3458
vendor-advisory
x_refsource_REDHAT
RHSA-2017:0832
vendor-advisory
x_refsource_REDHAT
97060
vdb-entry
x_refsource_BID
RHSA-2017:3455
vendor-advisory
x_refsource_REDHAT
RHSA-2017:3456
vendor-advisory
x_refsource_REDHAT
RHSA-2017:0873
vendor-advisory
x_refsource_REDHAT
RHSA-2017:3454
vendor-advisory
x_refsource_REDHAT
RHSA-2017:0830
vendor-advisory
x_refsource_REDHAT
RHSA-2017:0872
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now