UNKNOWNCVE-2026-28369
Undertow: undertow: request smuggling via malformed http request headers
Platform
java
Component
undertow
A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, which violates HTTP standards, can be exploited by a remote attacker to perform request smuggling. Request smuggling allows an attacker to bypass security mechanisms, access restricted information, or manipulate web caches, potentially leading to unauthorized actions or data exposure.
How to fix
Actualice Undertow a la versión corregida o superior. Consulte las notas de la versión de Red Hat build of Apache Camel for Spring Boot 4 y otros productos afectados para obtener instrucciones específicas de actualización. Aplique las actualizaciones de seguridad proporcionadas por Red Hat.
Monitor your dependencies automatically
Get notified when new vulnerabilities affect your projects. Free forever.
Start free