---
id: CVE-2026-3260
title: >-
  Rejected reason: The Undertow web server enforces a default maximum HTTP
  request entity size limit
summary: >-
  Rejected reason: The Undertow web server enforces a default maximum HTTP
  request entity size limit. Any request (including GET or HEAD) containing a
  body that exceeds this configurable limit is safely dropped by the server,
  preventing si…
severity: none
published: '2026-03-24'
updated: '2026-07-07'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-3260'
tags:
  - nvd
epss: 0.00441
epssPercentile: 0.3545
ingestedAt: '2026-07-07T21:43:23.194Z'
---

## Overview

Rejected reason: The Undertow web server enforces a default maximum HTTP request entity size limit. Any request (including GET or HEAD) containing a body that exceeds this configurable limit is safely dropped by the server, preventing single-request Resource Exhaustion (Out of Memory) Denial of Service attacks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
