PT-2026-70241 · Undertow+1 · Undertow+2

CVE-2026-14180

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Undertow HTTP server (affected versions not specified) WildFly (affected versions not specified) JBoss EAP (affected versions not specified)
Description A flaw exists in the ChunkReader component of the Undertow HTTP server, which is utilized by WildFly and JBoss EAP for handling chunked transfer encoding. The issue stems from the parser using a single internal variable to store both state flags and the remaining chunk size. An attacker can send a specially crafted request with an excessively large chunk size to cause these values to overlap, misleading the parser into believing a request has ended prematurely. This condition enables HTTP request smuggling, where a second request is processed out of sync, potentially bypassing security controls.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

HTTP Request/Response Smuggling

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14180

Affected Products

Jboss Eap
Undertow
Wildfly