{
  "@id": "urn:uuid:a5045f87-8a3e-42b7-95d4-340035474eba",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-24T09:31:26.931840+00:00",
  "statements": [
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/undertow-core@2.2.37.Final.tuxcare",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/undertow-core@2.2.37.Final.tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-3653 does not affect version 2.2.37.Final.tuxcare of io.undertow:undertow-core. not_affected \u2014 Target is Undertow 2.2.37.Final (TuxCare ELS branch 2.2.37.Final.tuxcare, HEAD c85edf915). CVE-2024-3653 is a remote memory-exhaustion DoS in LearningPushHandler: the pre-fix handler stored learned push resources in unbounded maps, so an attacker sending normal HTTP requests with many distinct paths/referrers could grow the cache without limit (default maxAge=-1 meant entries never expired and nothing capped the entry count). The upstream fix (UNDERTOW-2382) replaces the unbounded map with a bounded LRUCache<String, LRUCache<String, PushedRequest>> (default 200 entries) and makes max-entries/max-age configurable via system properties. This fix is ALREADY PRESENT in HEAD: LearningPushHandler.java:49-52,66,73 construct the bounded LRUCache, and LRUCache.add() (LRUCache.java:101-107) evicts the least-recently-used entry whenever cache.size() > maxEntries \u2014 bounding memory regardless of maxAge=-1. The fix commits 6d674f068 and 1da86edbd are ancestors of HEAD and, critically, ancestors of the upstream release base 4d04ea707 \"Prepare 2.2.37.Final\". They are authored by upstream maintainers (frainone@redhat.com, baranowb@gmail.com), NOT TuxCare. The TuxCare merge in HEAD (JAVAELSCVE-838) only edited core/pom.xml and did not touch the handler. Therefore the vulnerable pattern is not present; this is an upstream fix inherited from the shipped release \u2192 not_affected / code_not_present (not already_fixed, since no TuxCare-authored backport installed it). [VC re-run with claude-opus-4-8, prod prompt pin d46bd7a, 2026-09-16; Sonnet run failed the author gate (A2 onboarding-merge overclaim); applied manually after git verification]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-3653"
      },
      "impact_statement": "not_affected \u2014 Target is Undertow 2.2.37.Final (TuxCare ELS branch 2.2.37.Final.tuxcare, HEAD c85edf915). CVE-2024-3653 is a remote memory-exhaustion DoS in LearningPushHandler: the pre-fix handler stored learned push resources in unbounded maps, so an attacker sending normal HTTP requests with many distinct paths/referrers could grow the cache without limit (default maxAge=-1 meant entries never expired and nothing capped the entry count). The upstream fix (UNDERTOW-2382) replaces the unbounded map with a bounded LRUCache<String, LRUCache<String, PushedRequest>> (default 200 entries) and makes max-entries/max-age configurable via system properties. This fix is ALREADY PRESENT in HEAD: LearningPushHandler.java:49-52,66,73 construct the bounded LRUCache, and LRUCache.add() (LRUCache.java:101-107) evicts the least-recently-used entry whenever cache.size() > maxEntries \u2014 bounding memory regardless of maxAge=-1. The fix commits 6d674f068 and 1da86edbd are ancestors of HEAD and, critically, ancestors of the upstream release base 4d04ea707 \"Prepare 2.2.37.Final\". They are authored by upstream maintainers (frainone@redhat.com, baranowb@gmail.com), NOT TuxCare. The TuxCare merge in HEAD (JAVAELSCVE-838) only edited core/pom.xml and did not touch the handler. Therefore the vulnerable pattern is not present; this is an upstream fix inherited from the shipped release \u2192 not_affected / code_not_present (not already_fixed, since no TuxCare-authored backport installed it). [VC re-run with claude-opus-4-8, prod prompt pin d46bd7a, 2026-09-16; Sonnet run failed the author gate (A2 onboarding-merge overclaim); applied manually after git verification]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/undertow-core@2.2.37.Final.tuxcare",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/undertow-core@2.2.37.Final.tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-3884 affects version 2.2.37.Final.tuxcare of io.undertow:undertow-core.",
      "vulnerability": {
        "name": "CVE-2024-3884"
      },
      "action_statement": "Vulnerability CVE-2024-3884 affects version 2.2.37.Final.tuxcare of io.undertow:undertow-core."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/undertow-core@2.2.37.Final.tuxcare",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/undertow-core@2.2.37.Final.tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-4027 affects version 2.2.37.Final.tuxcare of io.undertow:undertow-core.",
      "vulnerability": {
        "name": "CVE-2024-4027"
      },
      "action_statement": "Vulnerability CVE-2024-4027 affects version 2.2.37.Final.tuxcare of io.undertow:undertow-core."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/undertow-core@2.2.37.Final.tuxcare",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/undertow-core@2.2.37.Final.tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-5971 does not affect version 2.2.37.Final.tuxcare of io.undertow:undertow-core. not_affected \u2014 Target Undertow 2.2.37.Final already contains the upstream fix for CVE-2024-5971. The vulnerability is a chunked-response hang: in SslConduit.wrapAndFlip() the SSLEngine.wrap loop could run multiple iterations (handshake-interleaved wraps, notably Java 17 TLSv1.3), but only the LAST iteration's SSLEngineResult was returned. Its bytesConsumed() under-reported the total application bytes actually consumed, so the write layer believed the body was not fully written and never emitted the chunked 0\\r\\n terminator \u2014 the connection hangs, causing uncontrolled resource consumption / DoS. The fix accumulates totalConsumedBytes across all wrap iterations and, if the final result's bytesConsumed differs, reconstructs the SSLEngineResult with the correct total so the write completes and the response terminates. HEAD's SslConduit.java (lines ~1002-1019) contains this fix verbatim. The fix commit 6742d8333 (\"[UNDERTOW-2413] CVE-2024-5971 ...\") is authored by Flavia Rainone <frainone@redhat.com>, a cherry-pick of upstream GitHub commit 74fdf630, and is an ancestor of the upstream \"Prepare 2.2.37.Final\" tag \u2014 i.e. shipped by upstream Red Hat before TuxCare onboarded the version. Verdict: not_affected (upstream/vendor fix already baked in), justification code_not_present. [VC re-run with claude-opus-4-8, prod prompt pin d46bd7a, 2026-09-16; Sonnet run failed the author gate (A2 onboarding-merge overclaim); applied manually after git verification]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-5971"
      },
      "impact_statement": "not_affected \u2014 Target Undertow 2.2.37.Final already contains the upstream fix for CVE-2024-5971. The vulnerability is a chunked-response hang: in SslConduit.wrapAndFlip() the SSLEngine.wrap loop could run multiple iterations (handshake-interleaved wraps, notably Java 17 TLSv1.3), but only the LAST iteration's SSLEngineResult was returned. Its bytesConsumed() under-reported the total application bytes actually consumed, so the write layer believed the body was not fully written and never emitted the chunked 0\\r\\n terminator \u2014 the connection hangs, causing uncontrolled resource consumption / DoS. The fix accumulates totalConsumedBytes across all wrap iterations and, if the final result's bytesConsumed differs, reconstructs the SSLEngineResult with the correct total so the write completes and the response terminates. HEAD's SslConduit.java (lines ~1002-1019) contains this fix verbatim. The fix commit 6742d8333 (\"[UNDERTOW-2413] CVE-2024-5971 ...\") is authored by Flavia Rainone <frainone@redhat.com>, a cherry-pick of upstream GitHub commit 74fdf630, and is an ancestor of the upstream \"Prepare 2.2.37.Final\" tag \u2014 i.e. shipped by upstream Red Hat before TuxCare onboarded the version. Verdict: not_affected (upstream/vendor fix already baked in), justification code_not_present. [VC re-run with claude-opus-4-8, prod prompt pin d46bd7a, 2026-09-16; Sonnet run failed the author gate (A2 onboarding-merge overclaim); applied manually after git verification]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/undertow-core@2.2.37.Final.tuxcare",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/undertow-core@2.2.37.Final.tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-12543 affects version 2.2.37.Final.tuxcare of io.undertow:undertow-core.",
      "vulnerability": {
        "name": "CVE-2025-12543"
      },
      "action_statement": "Vulnerability CVE-2025-12543 affects version 2.2.37.Final.tuxcare of io.undertow:undertow-core."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/undertow-core@2.2.37.Final.tuxcare",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/undertow-core@2.2.37.Final.tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-9784 affects version 2.2.37.Final.tuxcare of io.undertow:undertow-core.",
      "vulnerability": {
        "name": "CVE-2025-9784"
      },
      "action_statement": "Vulnerability CVE-2025-9784 affects version 2.2.37.Final.tuxcare of io.undertow:undertow-core."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/undertow-core@2.2.37.Final.tuxcare",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/undertow-core@2.2.37.Final.tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28367 affects version 2.2.37.Final.tuxcare of io.undertow:undertow-core.",
      "vulnerability": {
        "name": "CVE-2026-28367"
      },
      "action_statement": "Vulnerability CVE-2026-28367 affects version 2.2.37.Final.tuxcare of io.undertow:undertow-core."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/undertow-core@2.2.37.Final.tuxcare",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/undertow-core@2.2.37.Final.tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28368 affects version 2.2.37.Final.tuxcare of io.undertow:undertow-core.",
      "vulnerability": {
        "name": "CVE-2026-28368"
      },
      "action_statement": "Vulnerability CVE-2026-28368 affects version 2.2.37.Final.tuxcare of io.undertow:undertow-core."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/undertow-core@2.2.37.Final.tuxcare",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/undertow-core@2.2.37.Final.tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28369 affects version 2.2.37.Final.tuxcare of io.undertow:undertow-core.",
      "vulnerability": {
        "name": "CVE-2026-28369"
      },
      "action_statement": "Vulnerability CVE-2026-28369 affects version 2.2.37.Final.tuxcare of io.undertow:undertow-core."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/undertow-core@2.2.37.Final.tuxcare",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/undertow-core@2.2.37.Final.tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3260 affects version 2.2.37.Final.tuxcare of io.undertow:undertow-core.",
      "vulnerability": {
        "name": "CVE-2026-3260"
      },
      "action_statement": "Vulnerability CVE-2026-3260 affects version 2.2.37.Final.tuxcare of io.undertow:undertow-core."
    }
  ]
}
