CVE-2026-3260

UnknownEPSS 0.44%

Last modified

This CVE is reserved or rejected; no details have been published by NVD.

Description

Rejected reason: The Undertow web server enforces a default maximum HTTP request entity size limit. Any request (including GET or HEAD) containing a body that exceeds this configurable limit is safely dropped by the server, preventing single-request Resource Exhaustion (Out of Memory) Denial of Service attacks.

Metrics

EPSS Probability
0.44%

35.4th percentile

Probability of exploitation in the next 30 days. Learn more

Timeline

Published
Last Modified
Status
Rejected

Related CVEs from 2026

Are you affected by CVE-2026-3260?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST