PT-2026-28378 · Undertow · Undertow
Bzimport
·
Published
2026-03-27
·
Updated
2026-06-10
·
CVE-2026-28369
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Undertow (affected versions not specified)
Description
A flaw exists in Undertow where the software incorrectly processes HTTP requests containing leading spaces in the first header line, violating HTTP standards. This can be exploited to perform request smuggling, potentially allowing a remote attacker to bypass security mechanisms, access restricted information, or manipulate web caches, leading to unauthorized actions or data exposure. Request smuggling involves crafting malicious requests that are misinterpreted by the server, allowing an attacker to control how requests are processed.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
HTTP Request/Response Smuggling
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Undertow