PT-2026-28376 · Apache+2 · Apache Traffic Server+2

Published

2026-03-27

·

Updated

2026-04-06

·

CVE-2026-28367

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Undertow (affected versions not specified)
Description A flaw exists in Undertow that allows a remote attacker to exploit the software by sending rrr as a header block terminator. This can be used for request smuggling with certain proxy servers, such as older versions of Apache Traffic Server and Google Cloud Classic Application Load Balancer, potentially leading to unauthorized access or manipulation of web requests.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

HTTP Request/Response Smuggling

Weakness Enumeration

Related Identifiers

CVE-2026-28367
GHSA-3GV6-G396-9V4R

Affected Products

Apache Traffic Server
Google Cloud Classic Application Load Balancer
Undertow