Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-28368

Опубликовано: 27 авг. 2025
Источник: redhat
CVSS3: 8.7

Описание

A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header interpretation can be exploited to launch request smuggling attacks, potentially bypassing security controls and accessing unauthorized resources.

Отчет

This flaw in Undertow's header parsing logic allows for request smuggling attacks when Undertow is deployed behind an upstream proxy. Crafted requests can bypass security controls by being interpreted differently by Undertow and the proxy, potentially leading to unauthorized access or cache poisoning.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel for Spring Boot 4undertow-coreAffected
Red Hat build of Apache Camel - HawtIO 4undertow-coreAffected
Red Hat Data Grid 8undertow-coreAffected
Red Hat Enterprise Linux 10moditectNot affected
Red Hat Enterprise Linux 8pki-core:10.6/resteasyNot affected
Red Hat Enterprise Linux 8pki-deps:10.6/resteasyNot affected
Red Hat Enterprise Linux 9resteasyAffected
Red Hat Fuse 7undertow-coreAffected
Red Hat JBoss Enterprise Application Platform 7undertow-coreWill not fix
Red Hat JBoss Enterprise Application Platform 8org.jberet-jberet-parentAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-444
https://bugzilla.redhat.com/show_bug.cgi?id=2443261undertow: Undertow: Request smuggling via inconsistent header parsing

8.7 High

CVSS3

Связанные уязвимости

CVSS3: 8.7
nvd
4 дня назад

A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header interpretation can be exploited to launch request smuggling attacks, potentially bypassing security controls and accessing unauthorized resources.

CVSS3: 8.7
debian
4 дня назад

A flaw was found in Undertow. This vulnerability allows a remote attac ...

CVSS3: 8.7
github
4 дня назад

A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header interpretation can be exploited to launch request smuggling attacks, potentially bypassing security controls and accessing unauthorized resources.

8.7 High

CVSS3