Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
☕
☕ Maven
Not in CISA KEV
HIGH severity

CVE-2020-10705 — undertow-core

HIGH

CVE-2020-10705 is a high-severity (CVSS 7.5) CWE-770 vulnerability in io.undertow:undertow-core. A fix is available for io.undertow:undertow-core — see the affected versions and patch details below.

Allocation of Resources Without Limits or Throttling in Undertow

Also known asGHSA-g4cp-h53p-v3v8
Published
Updated
Affected
1 pkg
Patched
1 / 1
Exploits
None indexed
Exploitation data as of Oct 8, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

EPSS Exploitation Probability

via FIRST.org ↗
1.2%probability of exploitation in next 30 days
Lower Risk0.00%
Lower risk than most CVEs67th percentile — riskier than 67% of all scored CVEsHighest risk
0.00%0.56%1.13%1.69%0.3%1.2%Apr 26Aug 26Oct 26

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

How urgent is this, really

CVE-2020-10705 by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.

Where this sits among everything scored

Of 385,738 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.

Real-World Exposure

1 pkg affected
☕io.undertow:undertow-core

Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects Maven packages — download data is not available via public APIs for these ecosystems.

Description

A flaw was discovered in Undertow in versions before Undertow 2.1.1.Final where certain requests to the "Expect: 100-continue" header may cause an out of memory error. This flaw may potentially lead to a denial of service.

Affected Packages

1 total 1 fixed
EcosystemPackageVulnerable rangeFix
☕Mavenio.undertow:undertow-coreall versions2.1.1.Finalio.undertow:undertow-core:2.1.1.Final

Affected Products

4 products · 7 configurations
Application
oncommand insightnetapp
all
Application
jboss enterprise application platformredhat
1 version
7.2
Application
openshift application runtimesredhat
all
Application
undertowredhat
< 2.1.1
range

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for io.undertow:undertow-core, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Fix

    Update io.undertow:undertow-core to 2.1.1.Final or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2020-10705 is resolved across your whole dependency graph.

  3. Workarounds

    Cap what an attacker can consume: apply request size, rate and timeout limits in front of the affected component, and run it with memory and CPU limits so exhaustion degrades one worker rather than the whole service.

Fixing This On Your OS

If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.

Red HatImportant
Workaround published by Red Hat
There is currently no known mitigation for this security flaw.
Source: Red Hat security advisory for CVE-2020-10705 (CC BY 4.0)
ProductFixed inAdvisory
EAP-CD 20 Tech PreviewundertowRHSA-2020:3585
Red Hat JBoss EAP 7see advisoryRHSA-2020:2515
Red Hat JBoss EAP 7.2undertow-coreRHSA-2020:2061
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7eap7-apache-commons-beanutils-0:1.11.0-1.redhat_00001.1.ep7.el7RHSA-2025:16668
Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6eap7-activemq-artemis-0:2.9.0-4.redhat_00010.1.el6eapRHSA-2020:2058
Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 7eap7-activemq-artemis-0:2.9.0-4.redhat_00010.1.el7eapRHSA-2020:2059
Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 8eap7-activemq-artemis-0:2.9.0-4.redhat_00010.1.el8eapRHSA-2020:2060
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6eap7-activemq-artemis-0:2.9.0-4.redhat_00010.1.el6eapRHSA-2020:2511

Frequently Asked Questions

A flaw was discovered in Undertow in versions before Undertow 2.1.1.Final where certain requests to the "Expect: 100-continue" header may cause an out of memory error. This flaw may potentially lead to a denial of service.
O3 Security · Impact-Aware SCA

Is CVE-2020-10705 in your dependencies?

Find it across Maven, including transitive dependencies.

CVE-2020-10705: undertow-core DoS — Fixed in 2.1.1.Final