{"id":"CGA-g66f-55vc-2827","modified":"2026-09-07T01:36:20.845528026Z","published":"2026-01-22T11:56:23Z","upstream":["CVE-2024-3884","GHSA-6h4f-pj3g-q8fq"],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-3884"},{"type":"WEB","url":"https://github.com/undertow-io/undertow/pull/1894"},{"type":"WEB","url":"https://github.com/undertow-io/undertow/pull/1882"},{"type":"WEB","url":"https://github.com/undertow-io/undertow/pull/1860"},{"type":"WEB","url":"https://github.com/undertow-io/undertow/pull/1856"},{"type":"WEB","url":"https://github.com/undertow-io/undertow/commit/cb854c779b9e2368c3c274ebd7217c8e75d505be"},{"type":"WEB","url":"https://github.com/undertow-io/undertow/releases/tag/2.4.0.Beta1"},{"type":"WEB","url":"https://github.com/undertow-io/undertow/releases/tag/2.3.21.Final"},{"type":"WEB","url":"https://github.com/undertow-io/undertow/releases/tag/2.2.39.Final"},{"type":"PACKAGE","url":"https://github.com/undertow-io/undertow"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2275287"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2024-3884"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:6012"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:6011"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:4924"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:4917"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:4916"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:4915"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:3892"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:3891"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:3889"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:0386"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:0384"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:0383"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:3992"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:3990"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:22777"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:22775"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:22773"}],"affected":[{"package":{"name":"wildfly-openjdk-21","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/wildfly-openjdk-21?arch=x86_64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"39.0.0-r0"}]}],"ecosystem_specific":{"components":[{"component_location":"/usr/share/wildfly/bin/client/jboss-client.jar","component_purl":"pkg:maven/undertow-core@2.3.20.Final","latest_event_status":"fixed","latest_event_timestamp":"2026-01-29T23:11:27Z","component_name":"undertow-core","component_version":"2.3.20.Final","component_type":"java-archive"}]},"database_specific":{"source":"https://advisories.cgr.dev/chainguard/v3/osv/CGA-g66f-55vc-2827.json"}},{"package":{"name":"wildfly-openjdk-21","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/wildfly-openjdk-21?arch=x86_64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"39.0.0-r0"}]}],"ecosystem_specific":{"components":[{"component_purl":"pkg:maven/undertow-core@2.3.20.Final","latest_event_status":"fixed","latest_event_timestamp":"2026-01-29T23:11:27Z","component_name":"undertow-core","component_version":"2.3.20.Final","component_type":"java-archive","component_location":"/usr/share/wildfly/bin/client/jboss-client.jar"}]},"database_specific":{"source":"https://advisories.cgr.dev/chainguard/v3/osv/CGA-g66f-55vc-2827.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}