CVE-2026-28368

Published Mar 27, 2026

Last updated 4 days ago

Overview

Description
A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header interpretation can be exploited to launch request smuggling attacks, potentially bypassing security controls and accessing unauthorized resources.
Source
secalert@redhat.com
NVD status
Analyzed
Products
build_of_apache_camel_-_hawtio, build_of_apache_camel_for_spring_boot, data_grid, fuse, jboss_enterprise_application_platform, jboss_enterprise_application_platform_expansion_pack, process_automation, single_sign-on, undertow, enterprise_linux

Risk scores

CVSS 3.1

Type
Primary
Base score
9.1
Impact score
5.2
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity
CRITICAL

Weaknesses

secalert@redhat.com
CWE-444

Social media

Hype score
Not currently trending

Configurations