High severity7.5NVD Advisory· Published Mar 12, 2018· Updated Jun 17, 2026
CVE-2016-9589
CVE-2016-9589
Description
Undertow in Red Hat wildfly before version 11.0.0.Beta1 is vulnerable to a resource exhaustion resulting in a denial of service. Undertow keeps a cache of seen HTTP headers in persistent connections. It was found that this cache can easily exploited to fill memory with garbage, up to "max-headers" (default 200) * "max-header-size" (default 1MB) per active TCP connection.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.wildfly:wildfly-undertowMaven | < 11.0.0.Beta1 | 11.0.0.Beta1 |
Affected products
4cpe:2.3:a:redhat:jboss_wildfly_application_server:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:redhat:jboss_wildfly_application_server:*:*:*:*:*:*:*:*range: <=10.1.0
- cpe:2.3:a:redhat:jboss_wildfly_application_server:11.0.0:alpha1:*:*:*:*:*:*
- Red Hat, Inc./wildflyv5Range: 11.0.0.Beta1
Patches
Vulnerability mechanics
References
16- rhn.redhat.com/errata/RHSA-2017-0830.htmlnvdVendor AdvisoryWEB
- rhn.redhat.com/errata/RHSA-2017-0831.htmlnvdVendor AdvisoryWEB
- rhn.redhat.com/errata/RHSA-2017-0832.htmlnvdVendor AdvisoryWEB
- rhn.redhat.com/errata/RHSA-2017-0834.htmlnvdVendor AdvisoryWEB
- rhn.redhat.com/errata/RHSA-2017-0876.htmlnvdVendor AdvisoryWEB
- www.securityfocus.com/bid/97060nvdThird Party AdvisoryVDB Entry
- access.redhat.com/errata/RHSA-2017:0872nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2017:0873nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2017:3454nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2017:3455nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2017:3456nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2017:3458nvdVendor AdvisoryWEB
- github.com/advisories/GHSA-p4xg-cpr9-vwvjghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2016-9589ghsaADVISORY
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingWEB
- web.archive.org/web/20200227180917/https://www.securityfocus.com/bid/97060ghsaWEB
News mentions
0No linked articles in our index yet.