cbcvebase.
CVE-2026-28368
published 2026-03-27

CVE-2026-28368: A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by…

PriorityP262critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.70%
49.2th percentile
A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header interpretation can be exploited to launch request smuggling attacks, potentially bypassing security controls and accessing unauthorized resources.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianundertow
redhatbuild_of_apache_camel_for_spring_boot
redhatbuild_of_apache_camel_hawtio
redhatdata_grid
redhatenterprise_linux
redhatfuse
redhatjboss_enterprise_application_platform
redhatjboss_enterprise_application_platform
redhatprocess_automation
redhatsingle_sign-on

Detection & IOCsextracted from sources · hover to see the quote

  • Undertow splits header names from values on either space or colon, whichever comes first — detect crafted HTTP requests where a header name contains a space before the colon, making the header visible to Undertow but invisible to upstream proxies (request smuggling vector).
  • Monitor for HTTP request smuggling patterns in traffic between reverse proxies and Undertow backends — specifically requests where header interpretation differs between the proxy and Undertow due to space-delimited header name parsing.
  • Alert on Undertow deployments (undertow-core, resteasy packages) behind upstream proxies where crafted headers could bypass security controls — affected packages include undertow-core in Red Hat JBoss EAP 7/8, Red Hat Single Sign-On 7, Red Hat Process Automation 7, and resteasy on RHEL 9.
  • ·No mitigation is currently available that meets Red Hat Product Security criteria; patching via RHSA-2026:25125 and RHSA-2026:25126 is the recommended remediation for Red Hat JBoss EAP 8.1.

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
osv9.1CRITICAL
vendor_debian8.7HIGH
vendor_redhat8.7HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.