cbcvebase.
CVE-2026-28368
published 2026-03-27

CVE-2026-28368: A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by…

critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header interpretation can be exploited to launch request smuggling attacks, potentially bypassing security controls and accessing unauthorized resources.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianundertow
redhatbuild_of_apache_camel_for_spring_boot
redhatbuild_of_apache_camel_hawtio
redhatdata_grid
redhatenterprise_linux
redhatfuse
redhatjboss_enterprise_application_platform
redhatjboss_enterprise_application_platform
redhatprocess_automation
redhatsingle_sign-on

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
osv9.1CRITICAL