VYPR
High severity7.5NVD Advisory· Published Feb 23, 2021· Updated Jun 17, 2026

CVE-2020-27782

CVE-2020-27782

Description

A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes could be triggered by an attacker using query strings with non-RFC compliant characters resulting in a denial of service. The highest threat from this vulnerability is to system availability. This affects Undertow 2.1.5.SP1, 2.0.33.SP2, and 2.2.3.SP1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
io.undertow:undertow-coreMaven
>= 2.1.0, < 2.1.52.1.5
io.undertow:undertow-coreMaven
< 2.0.332.0.33

Affected products

8
  • cpe:2.3:a:redhat:jboss_fuse:6.0.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:redhat:jboss_fuse:6.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:jboss_fuse:7.0.0:*:*:*:*:*:*:*
  • cpe:2.3:a:redhat:openshift_application_runtimes:-:*:*:*:*:*:*:*
  • Red Hat/Undertow3 versions
    cpe:2.3:a:redhat:undertow:2.0.33:sp2:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:redhat:undertow:2.0.33:sp2:*:*:*:*:*:*
    • cpe:2.3:a:redhat:undertow:2.1.5:sp1:*:*:*:*:*:*
    • cpe:2.3:a:redhat:undertow:2.2.3:sp1:*:*:*:*:*:*
  • Undertow/Undertowdescription
  • ghsa-coords
    Range: >= 2.1.0, < 2.1.5

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.