{"id":"CVE-2019-14888","aliases":["GHSA-vjxc-frw4-jmh5"],"url":"https://o3.security/vulnerability/CVE-2019-14888","summary":"Undertow vulnerable to Uncontrolled Resource Consumption","details":"A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening on HTTPS. An attacker can target the HTTPS port to carry out a Denial Of Service (DOS) to make the service unavailable on SSL.","published":"2020-01-23T17:15:11.767Z","modified":"2026-07-08T05:54:54.027132198Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"io.undertow:undertow-core","fixedVersion":"2.0.29.Final"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2020:0729"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20220211-0001/"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14888"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:54:54.027132198Z"}}