GHSA-65h2-wf7m-q2v8 · Severity: high · Ecosystem: maven — Undertow vulnerable to denial of service
A flaw was found in undertow. Servlets annotated with @MultipartConfig may cause an OutOfMemoryError due to large multipart content. This may allow unauthorized users to cause remote Denial of Service (DoS) attack. If the server uses fileSizeThreshold to limit the file size, it's possible to bypass the limit by setting the file name in the request to null.
Conclusion & alert: CVE-2023-3223 is rated Moderate Risk (54.6/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.65%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-22 | 0.88% | 0.65% | -0.23% |
| 2 | 2025-11-21 | 6.46% | 0.88% | -5.58% |
| 3 | 2025-11-18 | — | 6.46% | — |
Full EPSS history (23 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
GHSA-65h2-wf7m-q2v8 · Severity: high · Ecosystem: maven — Undertow vulnerable to denial of service
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2023-3223 not yet assigned priority: Debian including 1 source packages (undertow), 2 status rows across 2 suites (forky, sid): resolved 2. | https://security-tracker.debian.org/tracker/CVE-2023-3223 |
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2023-3223 |
ubuntu
|
medium | CVE-2023-3223 medium priority: Ubuntu including 1 source packages (undertow), 12 status rows across 12 suites (bionic, focal, jammy, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): needs-triage 7, ignored 3, DNE 2. | https://ubuntu.com/security/CVE-2023-3223 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| redhat | undertow | < 2.2.24 | cpe:2.3:a:redhat:undertow:*:*:*:*:*:*:*:* |
| redhat | openshift_container_platform | 4.11 | cpe:2.3:a:redhat:openshift_container_platform:4.11:*:*:*:*:*:*:* |
| redhat | openshift_container_platform | 4.12 | cpe:2.3:a:redhat:openshift_container_platform:4.12:*:*:*:*:*:*:* |
| redhat | openshift_container_platform_for_ibm_linuxone | 4.9 | cpe:2.3:a:redhat:openshift_container_platform_for_ibm_linuxone:4.9:*:*:*:*:*:*:* |
| redhat | openshift_container_platform_for_ibm_linuxone | 4.10 | cpe:2.3:a:redhat:openshift_container_platform_for_ibm_linuxone:4.10:*:*:*:*:*:*:* |
| redhat | openshift_container_platform_for_power | 4.9 | cpe:2.3:a:redhat:openshift_container_platform_for_power:4.9:*:*:*:*:*:*:* |
| redhat | openshift_container_platform_for_power | 4.10 | cpe:2.3:a:redhat:openshift_container_platform_for_power:4.10:*:*:*:*:*:*:* |
| redhat | jboss_enterprise_application_platform_text-only_advisories | — | cpe:2.3:a:redhat:jboss_enterprise_application_platform_text-only_advisories:-:*:*:*:*:*:*:* |
| redhat | single_sign-on | — | cpe:2.3:a:redhat:single_sign-on:-:*:*:*:text-only:*:*:* |
| redhat | single_sign-on | 7.6 | cpe:2.3:a:redhat:single_sign-on:7.6:*:*:*:*:*:*:* |
| redhat | jboss_enterprise_application_platform | 7.4 | cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.4:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://access.redhat.com/errata/RHSA-2023:4505 | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2023:4506 | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2023:4507 | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2023:4509 | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2023:4918 | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2023:4919 | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2023:4920 | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2023:4921 | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2023:4924 | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2023:7247 | |
| https://access.redhat.com/security/cve/CVE-2023-3223 | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2209689 | Issue Tracking Vendor Advisory |
| https://security.netapp.com/advisory/ntap-20231027-0004/ |