Executive brief
Red Hat's Undertow is an HTTP server component used in enterprise Java application servers. A flaw in its HTTP/1.1 chunked-transfer decoder allows an unauthenticated remote attacker to exhaust server memory by sending specially crafted requests, causing the JVM to run out of memory and crashing all deployments on an affected listener.
Technical details
The vulnerability exists in Undertow's HTTP/1.1 chunked-transfer decoder, which lacks proper limits on the size and count of chunks. An unauthenticated attacker can exploit this via the network by sending HTTP requests with maliciously crafted chunked transfer encoding. The attack causes unbounded memory allocation in the JVM, triggering an OutOfMemory error that halts all deployments listening on the affected port. No authentication is required to exploit this vulnerability. Patches are expected to be available from Red Hat for affected Enterprise Application Platform versions.
Affected products
- Red Hat Enterprise Application Platform <UNKNOWN>
Timeline
- 2026-08-11: disclosed