{"id":"CVE-2026-3260","title":"Rejected reason: The Undertow web server enforces a default maximum HTTP request entity size limit","summary":"Rejected reason: The Undertow web server enforces a default maximum HTTP request entity size limit. Any request (including GET or HEAD) containing a body that exceeds this configurable limit is safely dropped by the server, preventing si…","severity":"none","published":"2026-03-24","updated":"2026-07-07","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-3260","tags":["nvd"],"epss":0.00441,"epssPercentile":0.3545,"ingestedAt":"2026-07-07T21:43:23.194Z","slug":"CVE-2026-3260","body":"## Overview\n\nRejected reason: The Undertow web server enforces a default maximum HTTP request entity size limit. Any request (including GET or HEAD) containing a body that exceeds this configurable limit is safely dropped by the server, preventing single-request Resource Exhaustion (Out of Memory) Denial of Service attacks.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}