CVE-2018-1114: Red Hat Undertow

Medium severity, CVSS 6.5. EPSS: 2.3% chance of exploitation in the next 30 days.

It was found that URLResource.getLastModified() in Undertow closes the file descriptors only when they are finalized which can cause file descriptors to exhaust. This leads to a file handler leak.

Affected products

  • Red Hat Undertow: affected versions not specified
  • Red Hat Virtualization: version 4.0 only; version 4.2 only
  • Red Hat Virtualization Host: version 4.0 only

Published 2018-09-11. Last modified 2026-06-17.