PT-2026-28378 · Undertow · Undertow

·

CVE-2026-28369

·

Published

2026-03-27

·

Updated

2026-07-22

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Undertow (affected versions not specified)
Description A flaw exists in Undertow where the software incorrectly processes HTTP requests containing leading spaces in the first header line, violating HTTP standards. This can be exploited to perform request smuggling, potentially allowing a remote attacker to bypass security mechanisms, access restricted information, or manipulate web caches, leading to unauthorized actions or data exposure. Request smuggling involves crafting malicious requests that are misinterpreted by the server, allowing an attacker to control how requests are processed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

HTTP Request/Response Smuggling

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-28369
GHSA-VQQJ-9CMV-HX43
RHSA-2026:25125

Affected Products

Undertow