io.undertow:undertow-servlet

Licenses: Apache-2.0

Direct Vulnerabilities

Known vulnerabilities in the io.undertow:undertow-servlet package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
NULL Pointer Dereference

[0,2.0.34.Final)[2.1.0.Final,2.1.6.Final)[2.2.0.Final,2.2.4.Final)
  • H
Denial of Service (DoS)

[,2.0.33.Final)[2.1.0.Final,2.1.5.Final)[2.2.0.Final,2.2.3.Final)
  • M
Security Bypass

[,2.1.0.Final)
  • H
Information Exposure

[,2.0.23.Final)
  • M
Directory Traversal

[1.0.0.Final,1.0.16.Final)

Package versions

336 VERSIONS IN TOTAL See all versions
versionpublisheddirect vulnerabilities
2.3.24.Final21 Mar, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
2.3.23.Final6 Feb, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
2.3.22.Final16 Jan, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
2.3.21.Final14 Jan, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
2.3.20.Final10 Oct, 2025
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
2.3.19.Final6 Sep, 2025
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
2.3.18.Final16 Oct, 2024
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
2.3.17.Final1 Sep, 2024
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
2.3.16.Final22 Aug, 2024
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
2.3.15.Final16 Jul, 2024
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L