V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2026-28369
DEB
Critical

A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorre…

CVSS
9.1
Critical
EPSS
0.01
p47
Published
2026-01-01
Updated
2026-01-01
Description

A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, which violates HTTP standards, can be exploited by a remote attacker to perform request smuggling. Request smuggling allows an attacker to bypass security mechanisms, access restricted information, or manipulate web caches, potentially leading to unauthorized actions or data exposure.

Tags · CWE
Pre-auth
CWE-444
CAPEC-33
CAPEC-273
Affected products
Build_of_apache_camel_-_hawtioBuild_of_apache_camel_for_spring_bootData_gridFuseJboss_enterprise_application_platformJboss_enterprise_application_platform_expansion_packProcess_automationSingle_sign-onUndertowEnterprise_linux
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Timeline
2026-01-01
Published
2026-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.007 · p47
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
undertowTracked
build_of_apache_camel_-_hawtio*Tracked
build_of_apache_camel_for_spring_boot*Tracked
data_grid*Tracked
enterprise_linux*Tracked
fuse*Tracked
jboss_enterprise_application_platform*Tracked
jboss_enterprise_application_platform_expansion_pack*Tracked
process_automation*Tracked
single_sign-on*Tracked
undertow*Tracked