Skip to content

Bump io.undertow:undertow-core from 2.3.24.Final to 2.4.0.Final#144

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/maven/io.undertow-undertow-core-2.4.0.Final
Open

Bump io.undertow:undertow-core from 2.3.24.Final to 2.4.0.Final#144
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/maven/io.undertow-undertow-core-2.4.0.Final

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 5, 2026

Copy link
Copy Markdown
Contributor

Bumps io.undertow:undertow-core from 2.3.24.Final to 2.4.0.Final.

Release notes

Sourced from io.undertow:undertow-core's releases.

v.2.4.0.Final

Release 2.4.0.Final Fixes CVE-2026-28367 CVE-2026-28368 CVE-2026-28369 Full list of Jiras: view in Jira

Release notes - Undertow - 2.4.0.Final

Feature Request

UNDERTOW-1593 Track processing time of in flight requests

UNDERTOW-1748 provide a way to "comment" a line in predicate language

UNDERTOW-1870 Hard-coded timeout for asynchronous HTTP requests - add async context timeout undertow option

UNDERTOW-1880 Undertow should support HTTP/2 connection management, wrt GOAWAY frame

UNDERTOW-1881 Add a new exchange attribute for SSL/TLS protocol version

UNDERTOW-2010 Provide method to invalidate all paths in CachingResourceManager

UNDERTOW-2242 Add UndertowOptions.ALLOW_ID_LESS_MATRIX_PARAMETERS

UNDERTOW-2273 Exchange Attribute parser doesn't handle nested attributes

UNDERTOW-2301 HTTP/2 cannot be configured on a per-listener basis

UNDERTOW-2319 Move io.undertow.multipart.minsize property to UndertowOptions

UNDERTOW-2553 Add rewriteHostHeader to ModCluster

UNDERTOW-2580 Support SameSite and custom cookie attributes

UNDERTOW-2696 Allow PathHandler to check for registered prefixes

UNDERTOW-2706 Add UndertowOptions_WEB_SOCKETS_READ_TIMEOUT

Component Upgrade

UNDERTOW-2584 Upgrade JBoss Threads to 3.9.1

UNDERTOW-2644 Upgrade wildfly openssl to 2.2.5.Final

Enhancement

UNDERTOW-1901 Add multipart support methods to ManagedServlet and HttpServerExchange signatures

UNDERTOW-1904 HttpSessionImpl use exception driven control

UNDERTOW-2110 Allow line breaks in predicates

... (truncated)

Commits
  • e2ae24e Prepare 2.4.0.Final
  • 3ece0bf Merge pull request #1947 from fl4via/UNDERTOW-2594_2.4.x
  • 4d35436 Merge pull request #3 from ropalka/UNDERTOW-1875_2.4.x
  • 0431672 [UNDERTOW-1875] Fix matrix parameters processing with comma
  • 335d198 [UNDERTOW-2594][UNDERTOW-2595][UNDERTOW-2596] At RequestParser, make sure the...
  • 14072a2 [UNDERTOW-2594][UNDERTOW-2595][UNDERTOW-2596] CVE-2026-28368 CVE-2026-28369 C...
  • 2e643b8 Next is 2.4.0.RC5
  • 15fc158 Prepare 2.4.0.RC4
  • 569361c Merge pull request #1942 from fl4via/UNDERTOW-2743
  • 6166aa9 [UNDERTOW-2743] At Cookies.parseCookie, remove the quotes from the cookie val...
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Jun 5, 2026
@dependabot dependabot Bot changed the title Bump io.undertow:undertow-core from 2.3.23.Final to 2.4.0.Final Bump io.undertow:undertow-core from 2.3.24.Final to 2.4.0.Final Jun 5, 2026
Bumps [io.undertow:undertow-core](https://github.com/undertow-io/undertow) from 2.3.24.Final to 2.4.0.Final.
- [Release notes](https://github.com/undertow-io/undertow/releases)
- [Commits](undertow-io/undertow@2.3.24.Final...2.4.0.Final)

---
updated-dependencies:
- dependency-name: io.undertow:undertow-core
  dependency-version: 2.4.0.Final
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/maven/io.undertow-undertow-core-2.4.0.Final branch from 6a4750b to d303dc0 Compare June 5, 2026 04:42
@sonarqubecloud

sonarqubecloud Bot commented Jun 5, 2026

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants