CVE-2024-4027 - CVE House
Back to Database
Status published High CVE-2024-4027

Undertow: outofmemoryerror in httpservletrequestimpl.getparameternames() can cause remote dos attacks

Vulnerability Description

A flaw was found in Undertow. Servlets using a method that calls HttpServletRequestImpl.getParameterNames() can cause an OutOfMemoryError when the client sends a request with large parameter names. This issue can be exploited by an unauthorized user to cause a remote denial-of-service (DoS) attack.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-4027

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

OpenShift Serverless, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apache Camel for Spring Boot 3, Red Hat build of Apache Camel for Spring Boot 4, Red Hat build of Apache Camel - HawtIO 4, Red Hat build of Apicurio Registry 2, Red Hat Build of Keycloak, Red Hat build of OptaPlanner 8, Red Hat build of Quarkus, Red Hat Data Grid 8, Red Hat Fuse 7, Red Hat Integration Camel K 1, Red Hat JBoss Data Grid 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat JBoss Enterprise Application Platform 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat JBoss Fuse Service Works 6, Red Hat Process Automation 7, Red Hat Single Sign-On 7, streams for Apache Kafka
Vulnerable Versions:
Unknown

Timeline

Official Publish: January 30th, 2026
Last Modified: July 15th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)