
CVE-2026-3260 A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending an HTTP GET request containing multipart/form-data content. If the underlyin… https://www.cve.org/CVERecord?id=CVE-2026-3260
Post summary
A new CVE in Undertow is disclosed, noting that remote attackers can exploit it via an HTTP GET request with multipart/form-data, but no patch, PoC, or active exploitation is reported.
