CVE-2024-4027Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in Undertow. Servlets using a method that calls HttpServletRequestImpl.getParameterNames() can cause an OutOfMemoryError when the client sends a request with large parameter names. This issue can be exploited by an unauthorized user to cause a remote denial-of-service (DoS) attack.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-01-30); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-01-30: 2Mentions · 2026-02-01: 1Technical Details · 2026-01-30: 2Technical Details · 2026-02-01: 101-3002-01
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-01-302
Disclosure2
2026-02-011
Disclosure1
Full discourse3 posts
  • PulsePatch.io@pulsepatchio
    Disclosure

    A denial of service vulnerability (CVE-2024-4027) affects Undertow. Servlets calling getParameterNames() can suffer an OutOfMemoryError with large parameter names. #Undertow #DoS #CVE https://www.pulsepatch.io/posts/cve-2024-4027-undertow-outofmemoryerror

    Post summary

    CVE-2024-4027 is a denial-of-service vulnerability in Undertow where large parameter names can cause an OutOfMemoryError, as detailed in the PulsePatch article.

    0000074
    1 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2024-4027 Undertow Servlet DoS Vulnerability via Large Parameter Names Exploitation https://vulmon.com/vulnerabilitydetails?qid=CVE-2024-4027

    Post summary

    The post announces CVE-2024-4027, a Denial‑of‑Service flaw in Undertow servlets triggered by large parameter names, with details hosted on a vulnerability database.

    0000064
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2024-4027 A flaw was found in Undertow. Servlets using a method that calls HttpServletRequestImpl.getParameterNames() can cause an OutOfMemoryError when the client sends a reques… https://www.cve.org/CVERecord?id=CVE-2024-4027

    Post summary

    The post announces CVE‑2024‑4027, a flaw in Undertow that triggers an OutOfMemoryError via HttpServletRequestImpl.getParameterNames(), but contains no PoC, exploit, patch, or evidence of active exploitation.

    00000225
    56.5K followersView on X

Explore more