Skip to content

Conversation

fl4via
Copy link
Member

@fl4via fl4via commented Sep 4, 2025

…sending a go away in case too many rst streams were sent to the client.

Jira: https://issues.redhat.com/browse/UNDERTOW-2598

@fl4via fl4via added bug fix Contains bug fix(es) next release This PR will be merged before next release or has already been merged (for payload double check) labels Sep 4, 2025
…sending a go away in case too many rst streams were sent to the client.

Signed-off-by: Flavia Rainone <[email protected]>
@fl4via fl4via added the on hold PR awaits non CI/Review holdover label Sep 4, 2025
@usr42
Copy link

usr42 commented Sep 9, 2025

Is CVE-2025-9784 already fixed in version 2.3.19.Final like suggested in https://issues.redhat.com/browse/UNDERTOW-2598? Or does this PR needs to be merged first and a version 2.3.20.Final needs to be released to fix the CVE?

@marcosgopen
Copy link

Is CVE-2025-9784 already fixed in version 2.3.19.Final like suggested in https://issues.redhat.com/browse/UNDERTOW-2598? Or does this PR needs to be merged first and a version 2.3.20.Final needs to be released to fix the CVE?

I think this still needs to be fixed (the issue is code in progress).

@gdiazsnap
Copy link

Hi, is there any plan to release this fix soon?

@wolfkor
Copy link

wolfkor commented Sep 23, 2025

We are also urgently waiting for a hotfix to resolve this high severity vulnerability

@lsainisnap
Copy link

We’re also eagerly awaiting a hotfix to fix this serious vulnerability. please merge and provide new fix version

@1kvsn
Copy link

1kvsn commented Sep 23, 2025

Hey team, are we going to fix this soon ?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug fix Contains bug fix(es) next release This PR will be merged before next release or has already been merged (for payload double check) on hold PR awaits non CI/Review holdover
Projects
None yet
Development

Successfully merging this pull request may close these issues.

7 participants