CVE-2026-5680

A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead to excessive memory consumption due to the PerMessageDeflateFunction.largerBuffer() method using exponential doubling, resulting in a Denial of Service (DoS) for the affected application.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-27 17:18

Updated : 2026-09-09 12:17


NVD link : CVE-2026-5680

Mitre link : CVE-2026-5680

CVE.ORG link : CVE-2026-5680


JSON object : View

Products Affected

No product.

CWE
CWE-770

Allocation of Resources Without Limits or Throttling