CVE-2026-28367
published 2026-03-27CVE-2026-28367: A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request…
PriorityP264critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.71%
49.2th percentile
A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certain proxy servers, such as older versions of Apache Traffic Server and Google Cloud Classic Application Load Balancer, potentially leading to unauthorized access or manipulation of web requests.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | undertow | — | — |
| redhat | build_of_apache_camel_for_spring_boot | — | — |
| redhat | build_of_apache_camel_hawtio | — | — |
| redhat | data_grid | — | — |
| redhat | fuse | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | process_automation | — | — |
| redhat | single_sign-on | — | — |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
\r\r\r
- →Detect HTTP requests using `\r\r\r` (three bare carriage returns) as a header block terminator, which Undertow incorrectly accepts and can be used for request smuggling. ↗
- →Focus detection on environments where Undertow is fronted by older Apache Traffic Server or Google Cloud Classic Application Load Balancer, as these proxies forward the malicious `\r\r\r` byte sequence. ↗
- ·The attack requires a proxy server in front of Undertow that forwards `\r\r\r` as a header block terminator. Mitigation is to configure proxies to reject or normalize non-standard header block terminators before forwarding to Undertow. ↗
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
osv9.1CRITICAL
vendor_debian8.7HIGH
vendor_redhat8.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Undertow Web Request request smuggling (Nessus ID 304100 / WID-SEC-2026-0907)
vuldb·2026-06-11·CVSS 9.1
CVE-2026-28367 [CRITICAL] Undertow Web Request request smuggling (Nessus ID 304100 / WID-SEC-2026-0907)
A vulnerability was found in Undertow. It has been classified as critical. Affected by this issue is some unknown functionality of the component Web Request Handler. The manipulation leads to http request smuggling.
This vulnerability is documented as CVE-2026-28367. The attack can be initiated remotely. There is not any exploit available.
GHSA
Undertow is Vulnerable to HTTP Request/Response Smuggling
ghsa·2026-03-27
CVE-2026-28367 [HIGH] CWE-444 Undertow is Vulnerable to HTTP Request/Response Smuggling
Undertow is Vulnerable to HTTP Request/Response Smuggling
A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certain proxy servers, such as older versions of Apache Traffic Server and Google Cloud Classic Application Load Balancer, potentially leading to unauthorized access or manipulation of web requests.
OSV
CVE-2026-28367: A flaw was found in Undertow
osv·2026-03-27·CVSS 9.1
CVE-2026-28367 [CRITICAL] CVE-2026-28367: A flaw was found in Undertow
A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certain proxy servers, such as older versions of Apache Traffic Server and Google Cloud Classic Application Load Balancer, potentially leading to unauthorized access or manipulation of web requests.
OSV
Undertow is Vulnerable to HTTP Request/Response Smuggling
osv·2026-03-27
CVE-2026-28367 [HIGH] Undertow is Vulnerable to HTTP Request/Response Smuggling
Undertow is Vulnerable to HTTP Request/Response Smuggling
A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certain proxy servers, such as older versions of Apache Traffic Server and Google Cloud Classic Application Load Balancer, potentially leading to unauthorized access or manipulation of web requests.
Debian
CVE-2026-28367: undertow - A flaw was found in Undertow. A remote attacker can exploit this vulnerability b...
vendor_debian·2026·CVSS 8.7
CVE-2026-28367 [HIGH] CVE-2026-28367: undertow - A flaw was found in Undertow. A remote attacker can exploit this vulnerability b...
A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certain proxy servers, such as older versions of Apache Traffic Server and Google Cloud Classic Application Load Balancer, potentially leading to unauthorized access or manipulation of web requests.
Scope: local
forky: open
sid: open
Red Hat
undertow: Undertow: Request smuggling via `\r\r\r` as a header block terminator
vendor_redhat·2025-08-27·CVSS 8.7
CVE-2026-28367 [HIGH] CWE-444 undertow: Undertow: Request smuggling via `\r\r\r` as a header block terminator
undertow: Undertow: Request smuggling via `\r\r\r` as a header block terminator
A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certain proxy servers, such as older versions of Apache Traffic Server and Google Cloud Classic Application Load Balancer, potentially leading to unauthorized access or manipulation of web requests.
A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certain proxy servers, such as older versions of Apache Traffic Server and Google Cloud Classic Application Load Balancer, potentially leading to unauthorized access or mani
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-28367 undertow: Undertow: Request smuggling via `\r\r\r` as a header block terminator
bugzilla·2026-02-27·CVSS 9.1
CVE-2026-28367 [CRITICAL] CVE-2026-28367 undertow: Undertow: Request smuggling via `\r\r\r` as a header block terminator
CVE-2026-28367 undertow: Undertow: Request smuggling via `\r\r\r` as a header block terminator
Undertow allows `\r\r\r` as a header block terminator. This can be used for request smuggling with proxy servers that forwards this byte sequence, including older versions of Apache Traffic Server and Google Cloud Classic Application Load Balancer.
Discussion:
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 8.1
Via RHSA-2026:25126 https://access.redhat.com/errata/RHSA-2026:25126
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8
Via RHSA-2026:25125 https://access.redhat.com/errata/RHSA-2026:25125
Wiz
CVE-2026-28367 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.7
CVE-2026-28367 [HIGH] CVE-2026-28367 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28367 :
Java vulnerability analysis and mitigation
\r\r\r
Source : NVD
## 8.7
Score
Published March 27, 2026
Severity HIGH
CNA Score 8.7
Affected Technologies
Java
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 14.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
io.undertow:undertow-parent
undertow
Sources
NVD
Debian 14 Severity HIGH No Fix Added at: Mar 29, 2026
Maven Severity HIGH No Fix Added at: Apr 02, 2026
Red Hat 8 Severity HIGH No Fix Added at: Mar 29, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Java vulnera
2026-03-27
Published