CVE-2026-3260
published 2026-03-24CVE-2026-3260: A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending an HTTP GET request containing multipart/form-data content. If the…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending an HTTP GET request containing multipart/form-data content. If the underlying application processes parameters using methods like `getParameterMap()`, the server prematurely parses and stores this content to disk. This could lead to resource exhaustion, potentially resulting in a Denial of Service (DoS).
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | undertow | — | — |
| redhat | build_of_apache_camel_for_spring_boot | — | — |
| redhat | build_of_apache_camel_hawtio | — | — |
| redhat | data_grid | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | fuse | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | process_automation | — | — |
| redhat | single_sign-on | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
undertow: Undertow: Denial of Service due to premature multipart/form-data parsing in GET requests
vendor_redhat·2026-03-24·CVSS 5.9
CVE-2026-3260 [MEDIUM] CWE-770 undertow: Undertow: Denial of Service due to premature multipart/form-data parsing in GET requests
undertow: Undertow: Denial of Service due to premature multipart/form-data parsing in GET requests
A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending an HTTP GET request containing multipart/form-data content. If the underlying application processes parameters using methods like `getParameterMap()`, the server prematurely parses and stores this content to disk. This could lead to resource exhaustion, potentially resulting in a Denial of Service (DoS).
A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending an HTTP GET request containing multipart/form-data content. If the underlying application processes parameters using methods like `getParameterMap()`, the server prematurely parses and stores this content to d
Debian
CVE-2026-3260: undertow - A flaw was found in Undertow. A remote attacker could exploit this vulnerability...
vendor_debian·2026·CVSS 5.9
CVE-2026-3260 [MEDIUM] CVE-2026-3260: undertow - A flaw was found in Undertow. A remote attacker could exploit this vulnerability...
A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending an HTTP GET request containing multipart/form-data content. If the underlying application processes parameters using methods like `getParameterMap()`, the server prematurely parses and stores this content to disk. This could lead to resource exhaustion, potentially resulting in a Denial of Service (DoS).
Scope: local
forky: open
sid: open
OSV
Undertow: Denial of Service via Multipart/Form-Data Parsing on HTTP GET Requests
osv·2026-03-24
CVE-2026-3260 [MEDIUM] Undertow: Denial of Service via Multipart/Form-Data Parsing on HTTP GET Requests
Undertow: Denial of Service via Multipart/Form-Data Parsing on HTTP GET Requests
A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending an HTTP GET request containing multipart/form-data content. If the underlying application processes parameters using methods like `getParameterMap()`, the server prematurely parses and stores this content to disk. This could lead to resource exhaustion, potentially resulting in a Denial of Service (DoS).
OSV
CVE-2026-3260: A flaw was found in Undertow
osv·2026-03-24·CVSS 7.5
CVE-2026-3260 [HIGH] CVE-2026-3260: A flaw was found in Undertow
A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending an HTTP GET request containing multipart/form-data content. If the underlying application processes parameters using methods like `getParameterMap()`, the server prematurely parses and stores this content to disk. This could lead to resource exhaustion, potentially resulting in a Denial of Service (DoS).
GHSA
Undertow: Denial of Service via Multipart/Form-Data Parsing on HTTP GET Requests
ghsa·2026-03-24
CVE-2026-3260 [MEDIUM] CWE-770 Undertow: Denial of Service via Multipart/Form-Data Parsing on HTTP GET Requests
Undertow: Denial of Service via Multipart/Form-Data Parsing on HTTP GET Requests
A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending an HTTP GET request containing multipart/form-data content. If the underlying application processes parameters using methods like `getParameterMap()`, the server prematurely parses and stores this content to disk. This could lead to resource exhaustion, potentially resulting in a Denial of Service (DoS).
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-3260 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.9
CVE-2026-3260 [MEDIUM] CVE-2026-3260 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3260 :
Java vulnerability analysis and mitigation
getParameterMap()
Source : NVD
## 5.9
Score
Published March 24, 2026
Severity MEDIUM
CNA Score 5.9
Affected Technologies
Java
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 71
Exploitation Probability (EPSS) 0.7
Affected packages and libraries
undertow
moditect
Sources
NVD
Debian 14 Severity MEDIUM No Fix Added at: Mar 26, 2026
Maven Severity MEDIUM Has Fix Added at: Mar 29, 2026
Red Hat 8, 9, 10 Severity MEDIUM No Fix Added at: Mar 24, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Java vu
Bugzilla
CVE-2026-3260 undertow: Undertow: Denial of Service due to premature multipart/form-data parsing in GET requests
bugzilla·2026-02-26·CVSS 7.5
CVE-2026-3260 [HIGH] CVE-2026-3260 undertow: Undertow: Denial of Service due to premature multipart/form-data parsing in GET requests
CVE-2026-3260 undertow: Undertow: Denial of Service due to premature multipart/form-data parsing in GET requests
A vulnerability was identified in Undertow (as used in Wildfly) where the server prematurely parses and stores multipart/form-data content to the disk when receiving an HTTP GET request, provided the underlying application (e.g., JSF) invokes parameter-parsing methods like getParameterMap().
2026-03-24
Published