Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-28368

Опубликовано: 27 авг. 2025
Источник: redhat
CVSS3: 8.7
EPSS Низкий

Описание

A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header interpretation can be exploited to launch request smuggling attacks, potentially bypassing security controls and accessing unauthorized resources.

Отчет

This flaw in Undertow's header parsing logic allows for request smuggling attacks when Undertow is deployed behind an upstream proxy. Crafted requests can bypass security controls by being interpreted differently by Undertow and the proxy, potentially leading to unauthorized access or cache poisoning.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel for Spring Boot 4undertow-coreFix deferred
Red Hat build of Apache Camel - HawtIO 4undertow-coreNot affected
Red Hat Data Grid 8undertow-coreWill not fix
Red Hat Enterprise Linux 10moditectNot affected
Red Hat Enterprise Linux 8pki-core:10.6/resteasyNot affected
Red Hat Enterprise Linux 8pki-deps:10.6/resteasyNot affected
Red Hat Enterprise Linux 9resteasyAffected
Red Hat Fuse 7undertow-coreWill not fix
Red Hat JBoss Enterprise Application Platform 7undertow-coreWill not fix
Red Hat JBoss Enterprise Application Platform 8org.jberet-jberet-parentAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-444
https://bugzilla.redhat.com/show_bug.cgi?id=2443261undertow: Undertow: Request smuggling via inconsistent header parsing

EPSS

Процентиль: 50%
0.00704
Низкий

8.7 High

CVSS3

Связанные уязвимости

CVSS3: 8.7
ubuntu
5 месяцев назад

A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header interpretation can be exploited to launch request smuggling attacks, potentially bypassing security controls and accessing unauthorized resources.

CVSS3: 8.7
nvd
5 месяцев назад

A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header interpretation can be exploited to launch request smuggling attacks, potentially bypassing security controls and accessing unauthorized resources.

CVSS3: 8.7
debian
5 месяцев назад

A flaw was found in Undertow. This vulnerability allows a remote attac ...

CVSS3: 8.7
github
5 месяцев назад

Undertow is Vulnerable to HTTP Request/Response Smuggling

EPSS

Процентиль: 50%
0.00704
Низкий

8.7 High

CVSS3