A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to handle chunked transfer encoding. The issue occurs because the parser uses a singl…
中危 CVSS 5.3
摘要
A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to handle chunked transfer encoding. The issue occurs because the parser uses a single internal variable to store both the remaining chunk size and state flags. By sending a specially crafted request with an extremely large chunk size, an attacker can cause these values to overlap, tricking the parser into thinking a request has finished prematurely. This can allow a second, "smuggl…
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
数据来源
- NVD DATABASE
原始链接
- https://access.redhat.com/errata/RHSA-2026:70228
- https://access.redhat.com/errata/RHSA-2026:70229
- https://access.redhat.com/errata/RHSA-2026:70230
- https://access.redhat.com/errata/RHSA-2026:70277
- https://access.redhat.com/security/cve/CVE-2026-14180
- https://bugzilla.redhat.com/show_bug.cgi?id=2494771
时间线
- nvd_ingest NVD