PT-2026-28376 · Apache+2 · Apache Traffic Server+2

CVE-2026-28367

·

Publicado

2026-03-27

·

Atualizado

2026-06-29

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Undertow (affected versions not specified)
Description A flaw exists in Undertow that allows a remote attacker to exploit the software by sending rrr as a header block terminator. This can be used for request smuggling with certain proxy servers, such as older versions of Apache Traffic Server and Google Cloud Classic Application Load Balancer, potentially leading to unauthorized access or manipulation of web requests.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

HTTP Request/Response Smuggling

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-28367
GHSA-3GV6-G396-9V4R
RHSA-2026:25125

Produtos afetados

Apache Traffic Server
Google Cloud Classic Application Load Balancer
Undertow