-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from missing hostname verification in HTTPS connections. The patches (GHSA-pfcc-3g6r-8rg8) explicitly add 'ENDPOINT_IDENTIFICATION_ALGORITHM=HTTPS' to client connection configurations. The vulnerable versions lacked this enforcement in HTTP/1.1 and HTTP/2 client providers, and in the SSL engine setup. The commit diffs show these functions were modified to add the missing validation, confirming they were the root cause.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| io.undertow:undertow-core | maven | >= 2.3.0, < 2.3.5.Final | 2.3.5.Final |
| io.undertow:undertow-core | maven | < 2.2.24.Final | 2.2.24.Final |