« Volver al listado

CVE-2026-3260

Estado: RechazadaSin puntuar—

Rejected reason: The Undertow web server enforces a default maximum HTTP request entity size limit. Any request (including GET or HEAD) containing a body that exceeds this configurable limit is safely dropped by the server, preventing single-request Resource Exhaustion (Out of Memory) Denial of Service attacks.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

FIRST aún no ha puntuado esta CVE (habitual en CVEs muy recientes o rechazadas).

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-3260",
  "cveTags": [],
  "metrics": {},
  "published": "2026-03-24T05:16:24.073",
  "references": [],
  "vulnStatus": "Rejected",
  "descriptions": [
    {
      "lang": "en",
      "value": "Rejected reason: The Undertow web server enforces a default maximum HTTP request entity size limit. Any request (including GET or HEAD) containing a body that exceeds this configurable limit is safely dropped by the server, preventing single-request Resource Exhaustion (Out of Memory) Denial of Service attacks."
    }
  ],
  "lastModified": "2026-07-07T21:16:56.140",
  "sourceIdentifier": "secalert@redhat.com"
}