PT-2026-28377 · Undertow · Undertow

Osidb Bzimport

·

Publicado

2026-03-27

·

Atualizado

2026-06-10

·

CVE-2026-28368

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Undertow (affected versions not specified)
Description A security issue exists in Undertow that allows a remote attacker to create malicious requests. The issue stems from discrepancies in how Undertow parses header names compared to upstream proxies, which can be exploited to launch request smuggling attacks. Successful exploitation could bypass security measures and grant access to unauthorized resources.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

HTTP Request/Response Smuggling

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-28368
GHSA-8V4X-MGVP-P658

Produtos afetados

Undertow