MEDIUM · 5.9

CVE-2026-3260

A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending an HTTP GET request containing multipart/form-data content. If the underlying application processes paramete...

Vulnerability Description

A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending an HTTP GET request containing multipart/form-data content. If the underlying application processes parameters using methods like `getParameterMap()`, the server prematurely parses and stores this content to disk. This could lead to resource exhaustion, potentially resulting in a Denial of Service (DoS).

CVSS Score

5.9

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
RedhatBuild Of Apache Camel - Hawtio4.0
RedhatBuild Of Apache Camel For Spring Boot4.0
RedhatData Grid8.0
RedhatFuse7.0.0
RedhatJboss Enterprise Application Platform7.0.0
RedhatJboss Enterprise Application Platform Expansion Pack-
RedhatProcess Automation7.0
RedhatSingle Sign-On7.0
RedhatUndertow-
RedhatEnterprise Linux8.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-3260?

CVE-2026-3260 is a vulnerability with a CVSS score of 5.9 (MEDIUM). A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending an HTTP GET request containing multipart/form-data content. If the underlying application processes paramete...

How severe is CVE-2026-3260?

CVE-2026-3260 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2026-3260?

Check the references section above for vendor advisories and patch information. Affected products include: Redhat Build Of Apache Camel - Hawtio, Redhat Build Of Apache Camel For Spring Boot, Redhat Data Grid, Redhat Fuse, Redhat Jboss Enterprise Application Platform.