VYPR
High severity7.5NVD Advisory· Published Jul 27, 2018· Updated Jun 17, 2026

CVE-2017-2670

CVE-2017-2670

Description

It was found in Undertow before 1.3.28 that with non-clean TCP close, the Websocket server gets into infinite loop on every IO thread, effectively causing DoS.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
io.undertow:undertow-coreMaven
< 1.3.281.3.28

Affected products

6
  • cpe:2.3:a:redhat:jboss_enterprise_application_platform:6.0.0:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:redhat:jboss_enterprise_application_platform:6.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.1.0:*:*:*:*:*:*:*
  • cpe:2.3:a:redhat:undertow:*:*:*:*:*:*:*:*
    Range: <1.3.28
  • cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  • ghsa-coords
    Range: < 1.3.28

Patches

Vulnerability mechanics

References

13

News mentions

0

No linked articles in our index yet.