CVE-2026-28369
published 2026-03-27CVE-2026-28369: A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the…
PriorityP261critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.68%
48.2th percentile
A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, which violates HTTP standards, can be exploited by a remote attacker to perform request smuggling. Request smuggling allows an attacker to bypass security mechanisms, access restricted information, or manipulate web caches, potentially leading to unauthorized actions or data exposure.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | undertow | — | — |
| redhat | build_of_apache_camel_for_spring_boot | — | — |
| redhat | build_of_apache_camel_hawtio | — | — |
| redhat | data_grid | — | — |
| redhat | enterprise_linux | — | — |
| redhat | fuse | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | process_automation | — | — |
| redhat | single_sign-on | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect HTTP requests where the first header line begins with one or more leading spaces — Undertow incorrectly strips these instead of rejecting the request, enabling request smuggling ↗
- →Flag any HTTP request where the first header field-line starts with a space or tab character (obs-fold on the first line); per RFC this is always invalid and should be rejected, not silently stripped ↗
- ·undertow-core in Red Hat build of Apache Camel - HawtIO 4 is confirmed Not Affected ↗
- ·undertow-core in Red Hat JBoss Enterprise Application Platform 7 is marked 'Will not fix' ↗
- ·Fix is available for Red Hat JBoss Enterprise Application Platform 8.1 via RHSA-2026:25126 and RHSA-2026:25125 ↗
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
osv9.1CRITICAL
vendor_debian8.7HIGH
vendor_redhat8.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Undertow HTTP Request request smuggling (Nessus ID 304080 / WID-SEC-2026-0907)
vuldb·2026-06-11·CVSS 9.1
CVE-2026-28369 [CRITICAL] Undertow HTTP Request request smuggling (Nessus ID 304080 / WID-SEC-2026-0907)
A vulnerability identified as critical has been detected in Undertow. This affects an unknown function of the component HTTP Request Handler. The manipulation leads to http request smuggling.
This vulnerability is traded as CVE-2026-28369. It is possible to initiate the attack remotely. There is no exploit available.
OSV
CVE-2026-28369: A flaw was found in Undertow
osv·2026-03-27·CVSS 9.1
CVE-2026-28369 [CRITICAL] CVE-2026-28369: A flaw was found in Undertow
A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, which violates HTTP standards, can be exploited by a remote attacker to perform request smuggling. Request smuggling allows an attacker to bypass security mechanisms, access restricted information, or manipulate web caches, potentially leading to unauthorized actions or data exposure.
OSV
Undertow is Vulnerable to HTTP Request/Response Smuggling
osv·2026-03-27
CVE-2026-28369 [HIGH] Undertow is Vulnerable to HTTP Request/Response Smuggling
Undertow is Vulnerable to HTTP Request/Response Smuggling
A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, which violates HTTP standards, can be exploited by a remote attacker to perform request smuggling. Request smuggling allows an attacker to bypass security mechanisms, access restricted information, or manipulate web caches, potentially leading to unauthorized actions or data exposure.
GHSA
Undertow is Vulnerable to HTTP Request/Response Smuggling
ghsa·2026-03-27
CVE-2026-28369 [HIGH] CWE-444 Undertow is Vulnerable to HTTP Request/Response Smuggling
Undertow is Vulnerable to HTTP Request/Response Smuggling
A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, which violates HTTP standards, can be exploited by a remote attacker to perform request smuggling. Request smuggling allows an attacker to bypass security mechanisms, access restricted information, or manipulate web caches, potentially leading to unauthorized actions or data exposure.
Debian
CVE-2026-28369: undertow - A flaw was found in Undertow. When Undertow receives an HTTP request where the f...
vendor_debian·2026·CVSS 8.7
CVE-2026-28369 [HIGH] CVE-2026-28369: undertow - A flaw was found in Undertow. When Undertow receives an HTTP request where the f...
A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, which violates HTTP standards, can be exploited by a remote attacker to perform request smuggling. Request smuggling allows an attacker to bypass security mechanisms, access restricted information, or manipulate web caches, potentially leading to unauthorized actions or data exposure.
Scope: local
forky: open
sid: open
Red Hat
undertow: Undertow: Request Smuggling via Malformed HTTP Request Headers
vendor_redhat·2025-08-27·CVSS 8.7
CVE-2026-28369 [HIGH] CWE-444 undertow: Undertow: Request Smuggling via Malformed HTTP Request Headers
undertow: Undertow: Request Smuggling via Malformed HTTP Request Headers
A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, which violates HTTP standards, can be exploited by a remote attacker to perform request smuggling. Request smuggling allows an attacker to bypass security mechanisms, access restricted information, or manipulate web caches, potentially leading to unauthorized actions or data exposure.
A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, which v
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-28369 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.7
CVE-2026-28369 [HIGH] CVE-2026-28369 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28369 :
Java vulnerability analysis and mitigation
A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, which violates HTTP standards, can be exploited by a remote attacker to perform request smuggling. Request smuggling allows an attacker to bypass security mechanisms, access restricted information, or manipulate web caches, potentially leading to unauthorized actions or data exposure.
Source : NVD
## 9.1
Score
Published March 27, 2026
Severity CRITICAL
CNA Score 8.7
Affected Technologies
Java
NixOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploit
Wiz
CVE-2026-4366 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.7
CVE-2026-4366 [HIGH] CVE-2026-4366 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-4366 :
JBoss EAP vulnerability analysis and mitigation
A flaw was identified in Keycloak, an identity and access management solution, where it improperly follows HTTP redirects when processing certain client configuration requests. This behavior allows an attacker to trick the server into making unintended requests to internal or restricted resources. As a result, sensitive internal services such as cloud metadata endpoints could be accessed. This issue may lead to information disclosure and enable attackers to map internal network infrastructure.
Source : NVD
## 5.8
Score
Published March 18, 2026
Severity MEDIUM
CNA Score 5.8
Affected Technologies
JBoss EAP
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitati
Bugzilla
CVE-2026-28369 undertow: Undertow: Request Smuggling via Malformed HTTP Request Headers
bugzilla·2026-02-27·CVSS 9.1
CVE-2026-28369 [CRITICAL] CVE-2026-28369 undertow: Undertow: Request Smuggling via Malformed HTTP Request Headers
CVE-2026-28369 undertow: Undertow: Request Smuggling via Malformed HTTP Request Headers
When Undertow receives a request in which the first header line begins
with one or more spaces, it strips them before processing the request.
This is usable as a request smuggling primitive.
The HTTP RFCs state that when a field-line begins with a space or tab,
it is permissible to concatenate it into the previous field-line's
value. This is referred to as `obs-fold` in the RFCs. However, it is
always invalid to obs-fold on the first line, since there is no
previous field-line to concatenate into. Thus, the message should be
rejected.
Discussion:
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 8.1
Via RHSA-2026:25126 https://access.redhat.com/
2026-03-27
Published