Red Hat Bugzilla – Bug 1638391
CVE-2018-12541 vertx: WebSocket HTTP upgrade implementation holds the entire http request in memory before the handshake
Last modified: 2018-10-18 04:15:02 EDT
It was found that the WebSocket HTTP upgrade implementation buffers the full http request before doing the handshake, holding the entire request body in memory. Upstream issue: https://github.com/eclipse-vertx/vert.x/issues/2648 References: https://bugs.eclipse.org/bugs/show_bug.cgi?id=539170 Upstream patch: https://github.com/eclipse-vertx/vert.x/commit/269a583330695d1418a4f5578f7169350b2e1332
This issue has been addressed in the following products: Red Hat Openshift Application Runtimes (text-only advisories) Via RHSA-2018:2946 https://access.redhat.com/errata/RHSA-2018:2946