CVE-2026-28368
published 2026-03-27CVE-2026-28368: A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by…
PriorityP262critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.70%
49.2th percentile
A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header interpretation can be exploited to launch request smuggling attacks, potentially bypassing security controls and accessing unauthorized resources.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | undertow | — | — |
| redhat | build_of_apache_camel_for_spring_boot | — | — |
| redhat | build_of_apache_camel_hawtio | — | — |
| redhat | data_grid | — | — |
| redhat | enterprise_linux | — | — |
| redhat | fuse | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | process_automation | — | — |
| redhat | single_sign-on | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Undertow splits header names from values on either space or colon, whichever comes first — detect crafted HTTP requests where a header name contains a space before the colon, making the header visible to Undertow but invisible to upstream proxies (request smuggling vector). ↗
- →Monitor for HTTP request smuggling patterns in traffic between reverse proxies and Undertow backends — specifically requests where header interpretation differs between the proxy and Undertow due to space-delimited header name parsing. ↗
- →Alert on Undertow deployments (undertow-core, resteasy packages) behind upstream proxies where crafted headers could bypass security controls — affected packages include undertow-core in Red Hat JBoss EAP 7/8, Red Hat Single Sign-On 7, Red Hat Process Automation 7, and resteasy on RHEL 9. ↗
- ·No mitigation is currently available that meets Red Hat Product Security criteria; patching via RHSA-2026:25125 and RHSA-2026:25126 is the recommended remediation for Red Hat JBoss EAP 8.1. ↗
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
osv9.1CRITICAL
vendor_debian8.7HIGH
vendor_redhat8.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Undertow Requests request smuggling (Nessus ID 304101 / WID-SEC-2026-0907)
vuldb·2026-06-11·CVSS 9.1
CVE-2026-28368 [CRITICAL] Undertow Requests request smuggling (Nessus ID 304101 / WID-SEC-2026-0907)
A vulnerability described as critical has been identified in Undertow. This affects an unknown function of the component Requests Handler. The manipulation results in http request smuggling.
This vulnerability was named CVE-2026-28368. The attack may be performed from remote. There is no available exploit.
GHSA
Undertow is Vulnerable to HTTP Request/Response Smuggling
ghsa·2026-03-27
CVE-2026-28368 [HIGH] CWE-444 Undertow is Vulnerable to HTTP Request/Response Smuggling
Undertow is Vulnerable to HTTP Request/Response Smuggling
A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header interpretation can be exploited to launch request smuggling attacks, potentially bypassing security controls and accessing unauthorized resources.
OSV
CVE-2026-28368: A flaw was found in Undertow
osv·2026-03-27·CVSS 9.1
CVE-2026-28368 [CRITICAL] CVE-2026-28368: A flaw was found in Undertow
A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header interpretation can be exploited to launch request smuggling attacks, potentially bypassing security controls and accessing unauthorized resources.
OSV
Undertow is Vulnerable to HTTP Request/Response Smuggling
osv·2026-03-27
CVE-2026-28368 [HIGH] Undertow is Vulnerable to HTTP Request/Response Smuggling
Undertow is Vulnerable to HTTP Request/Response Smuggling
A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header interpretation can be exploited to launch request smuggling attacks, potentially bypassing security controls and accessing unauthorized resources.
Debian
CVE-2026-28368: undertow - A flaw was found in Undertow. This vulnerability allows a remote attacker to con...
vendor_debian·2026·CVSS 8.7
CVE-2026-28368 [HIGH] CVE-2026-28368: undertow - A flaw was found in Undertow. This vulnerability allows a remote attacker to con...
A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header interpretation can be exploited to launch request smuggling attacks, potentially bypassing security controls and accessing unauthorized resources.
Scope: local
forky: open
sid: open
Red Hat
undertow: Undertow: Request smuggling via inconsistent header parsing
vendor_redhat·2025-08-27·CVSS 8.7
CVE-2026-28368 [HIGH] CWE-444 undertow: Undertow: Request smuggling via inconsistent header parsing
undertow: Undertow: Request smuggling via inconsistent header parsing
A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header interpretation can be exploited to launch request smuggling attacks, potentially bypassing security controls and accessing unauthorized resources.
A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header interpretation can be exploited to launch request smuggling attacks, potentially bypassing security controls and accessing unauthor
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-4366 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.7
CVE-2026-4366 [HIGH] CVE-2026-4366 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-4366 :
JBoss EAP vulnerability analysis and mitigation
A flaw was identified in Keycloak, an identity and access management solution, where it improperly follows HTTP redirects when processing certain client configuration requests. This behavior allows an attacker to trick the server into making unintended requests to internal or restricted resources. As a result, sensitive internal services such as cloud metadata endpoints could be accessed. This issue may lead to information disclosure and enable attackers to map internal network infrastructure.
Source : NVD
## 5.8
Score
Published March 18, 2026
Severity MEDIUM
CNA Score 5.8
Affected Technologies
JBoss EAP
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitati
Wiz
CVE-2026-28368 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.7
CVE-2026-28368 [HIGH] CVE-2026-28368 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28368 :
Java vulnerability analysis and mitigation
A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header interpretation can be exploited to launch request smuggling attacks, potentially bypassing security controls and accessing unauthorized resources.
Source : NVD
## 9.1
Score
Published March 27, 2026
Severity CRITICAL
CNA Score 8.7
Affected Technologies
Java
NixOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 29.1
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
pki-deps:10.6::res
Bugzilla
CVE-2026-28368 undertow: Undertow: Request smuggling via inconsistent header parsing
bugzilla·2026-02-27·CVSS 9.1
CVE-2026-28368 [CRITICAL] CVE-2026-28368 undertow: Undertow: Request smuggling via inconsistent header parsing
CVE-2026-28368 undertow: Undertow: Request smuggling via inconsistent header parsing
Undertow splits header names from values on either space or colon, whichever comes first. This allows for the construction of crafted requests with headers that are visible only to Undertow, but not upstream proxies, which can be used to launch request smuggling attacks.
Discussion:
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 8.1
Via RHSA-2026:25126 https://access.redhat.com/errata/RHSA-2026:25126
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8
Via RHSA-2026:25125 https://access.redhat.com/errata/RHSA-2026:
2026-03-27
Published