PT-2026-28378 · Undertow · Undertow

Bzimport

·

Published

2026-03-27

·

Updated

2026-06-10

·

CVE-2026-28369

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Undertow (affected versions not specified)
Description A flaw exists in Undertow where the software incorrectly processes HTTP requests containing leading spaces in the first header line, violating HTTP standards. This can be exploited to perform request smuggling, potentially allowing a remote attacker to bypass security mechanisms, access restricted information, or manipulate web caches, leading to unauthorized actions or data exposure. Request smuggling involves crafting malicious requests that are misinterpreted by the server, allowing an attacker to control how requests are processed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

HTTP Request/Response Smuggling

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-28369
GHSA-VQQJ-9CMV-HX43

Affected Products

Undertow