CVE-2024-3884 - CVE House
Back to Database
Status published High CVE-2024-3884

Undertow: outofmemory when parsing form data encoding with application/x-www-form-urlencoded

Vulnerability Description

A flaw was found in Undertow that can cause remote denial of service attacks. When the server uses the FormEncodedDataDefinition.doParse(StreamSourceChannel) method to parse large form data encoding with application/x-www-form-urlencoded, the method will cause an OutOfMemory issue. This flaw allows unauthorized users to cause a remote denial of service (DoS) attack.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-3884

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Red Hat JBoss Enterprise Application Platform, Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7, Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7, Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7, Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8, Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9, Red Hat JBoss Enterprise Application Platform 8.0, Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8, Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9, Red Hat JBoss Enterprise Application Platform 8.1, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, OpenShift Serverless, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apache Camel for Spring Boot 3, Red Hat build of Apache Camel for Spring Boot 4, Red Hat build of Apache Camel - HawtIO 4, Red Hat build of Apicurio Registry 2, Red Hat Build of Keycloak, Red Hat build of OptaPlanner 8, Red Hat build of Quarkus, Red Hat Data Grid 8, Red Hat Fuse 7, Red Hat Integration Camel K 1, Red Hat Integration Camel Quarkus 2, Red Hat JBoss Data Grid 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat JBoss Fuse Service Works 6, Red Hat Process Automation 7, Red Hat Single Sign-On 7, streams for Apache Kafka
Vulnerable Versions:
2.2.39.Final-redhat-00001, 0:1.4.18-19.SP17_redhat_00001.1.ep7.el7, 0:7.1.14-4.GA_redhat_00003.1.ep7.el7, 0:2.0.41-7.SP8_redhat_00001.1.el7eap, 0:7.3.17-5.GA_redhat_00006.1.el7eap, 0:2.2.39-1.Final_redhat_00001.1.el7eap, 0:7.4.24-4.GA_redhat_00002.1.el7eap, 0:2.2.39-1.Final_redhat_00001.1.el8eap, 0:7.4.24-4.GA_redhat_00002.1.el8eap, 0:2.2.39-1.Final_redhat_00001.1.el9eap, 0:7.4.24-4.GA_redhat_00002.1.el9eap, 0:1.83.0-1.redhat_00001.1.el8eap, 0:33.0.0-2.jre_redhat_00003.1.el8eap, 0:4.0.6-1.redhat_00001.1.el8eap, 0:1.0.0-3.redhat_00009.1.el8eap, 0:2.0.2-1.Final_redhat_00001.1.el8eap, 0:2.3.23-1.SP3_redhat_00001.1.el8eap, 0:1.83.0-1.redhat_00001.1.el9eap, 0:33.0.0-2.jre_redhat_00003.1.el9eap, 0:4.0.6-1.redhat_00001.1.el9eap, 0:1.0.0-3.redhat_00009.1.el9eap, 0:2.0.2-1.Final_redhat_00001.1.el9eap, 0:2.3.23-1.SP3_redhat_00001.1.el9eap, 0:4.0.10-1.redhat_00001.1.el8eap, 0:1.82.0-1.redhat_00001.1.el8eap, 0:801.3.0-1.GA_redhat_00001.1.el8eap, 0:1.0.1-3.redhat_00003.1.el8eap, 0:6.6.36-1.Final_redhat_00001.1.el8eap, 0:4.0.2-1.Final_redhat_00001.1.el8eap, 0:2.5.0-1.redhat_00001.1.el8eap, 0:2.3.20-2.SP4_redhat_00001.1.el8eap, 0:8.1.3-4.GA_redhat_00006.1.el8eap, 0:5.0.12-1.Final_redhat_00001.1.el8eap, 0:2.6.6-1.Final_redhat_00001.1.el8eap, 0:8.1.1-4.GA_redhat_00007.1.el8eap, 0:4.0.10-1.redhat_00001.1.el9eap, 0:1.82.0-1.redhat_00001.1.el9eap, 0:801.3.0-1.GA_redhat_00001.1.el9eap, 0:1.0.1-3.redhat_00003.1.el9eap, 0:6.6.36-1.Final_redhat_00001.1.el9eap, 0:4.0.2-1.Final_redhat_00001.1.el9eap, 0:2.5.0-1.redhat_00001.1.el9eap, 0:2.3.20-2.SP4_redhat_00001.1.el9eap, 0:8.1.3-4.GA_redhat_00006.1.el9eap, 0:5.0.12-1.Final_redhat_00001.1.el9eap, 0:2.6.6-1.Final_redhat_00001.1.el9eap, 0:8.1.1-4.GA_redhat_00007.1.el9eap

Timeline

Official Publish: December 3rd, 2025
Last Modified: July 7th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)