← Back

CVE-2026-28368

nvd nist
Published: Mar 27, 2026Modified: Jun 29, 2026

JSON object

Loading...
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 3.9 / Impact: 5.2
Source: NVD

Description

A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header interpretation can be exploited to launch request smuggling attacks, potentially bypassing security controls and accessing unauthorized resources.

Affected (11)

10 products
Build Of Apache Camel Hawtio
Data Grid
Enterprise Linux
Fuse
Process Automation
Single Sign On
Undertow
Configuration A
11 vulnerable

References (4)

Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Issue TrackingVendor Advisory

Timeline

No history available yet.