PT-2026-28377 · Undertow · Undertow

Osidb Bzimport

·

Published

2026-03-27

·

Updated

2026-06-10

·

CVE-2026-28368

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Undertow (affected versions not specified)
Description A security issue exists in Undertow that allows a remote attacker to create malicious requests. The issue stems from discrepancies in how Undertow parses header names compared to upstream proxies, which can be exploited to launch request smuggling attacks. Successful exploitation could bypass security measures and grant access to unauthorized resources.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

HTTP Request/Response Smuggling

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-28368
GHSA-8V4X-MGVP-P658

Affected Products

Undertow