CVE-2019-19343 PUBLISHED

A flaw was found in Undertow when using Remoting as shipped in Red Hat Jboss EAP before version 7.2.4. A memory leak in HttpOpenListener due to holding remote connections indefinitely may lead to denial of service. Versions before undertow 2.0.25.SP1 and jboss-remoting 5.0.14.SP1 are believed to be vulnerable.

EPSS 0.51% · 66.1th percentile

Risk Scores

EPSS Score
0.51%
66.1th percentile

Affected Products

VendorProductVersions
Ubuntu:24.04:LTSundertow2.3.8-2, 0
Ubuntu:25.10undertow2.3.18-2, 2.3.18-1, 0
Ubuntu:16.04:LTSundertow1.3.16-1, 0, 1.3.4-1
Ubuntu:22.04:LTSundertow2.2.14-1, 2.2.16-1, 0
Ubuntu:20.04:LTSundertow2.0.29-1, 0, 2.0.23-1
Ubuntu:18.04:LTSundertow0, 1.4.23-3, 1.4.23-1

Timeline

References

Open in Interactive Console →