Hi Pawan,
The CVE-2024-7885 issue is not yet fixed in Undertow, although I know the Undertow community is looking into it. Once Undertow does a release with a fix for that included, we'll evaluate how to incorporate it into WildFly. Until that happens I don't know for sure, but it seems reasonable that the fix will land in WildFly 34, which we expect to release in the first half of October.
Note that our understanding is CVE-2024-7885 only affects servers that have enabled the AJP listener.
Best regards,
Brian