CVE-2017-2670 PUBLISHED

It was found in Undertow before 1.3.28 that with non-clean TCP close, the Websocket server gets into infinite loop on every IO thread, effectively causing DoS.

EPSS 5.97% · 90.6th percentile

Risk Scores

EPSS Score
5.97%
90.6th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSundertow0, 1.3.4-1, 1.3.5-1
Ubuntu:24.04:LTSundertow0, 2.3.8-2

Timeline

References

Open in Interactive Console →