CVE-2026-28369 Details
Description
A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, which violates HTTP standards, can be exploited by a remote attacker to perform request smuggling. Request smuggling allows an attacker to bypass security mechanisms, access restricted information, or manipulate web caches, potentially leading to unauthorized actions or data exposure.
A request smuggling vulnerability has been identified in Undertow. The issue arises when the server receives an HTTP request with the first header line starting with one or more spaces. Undertow improperly processes these requests by removing the leading spaces, creating a loophole that can be exploited by remote attackers. This behavior contradicts HTTP standards, as the specifications allow such leading spaces to be concatenated into the previous header line's value, except for the first line. Exploiting this flaw can enable attackers to bypass security measures, access restricted information, manipulate web caches, and potentially execute unauthorized actions or expose sensitive data.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-444 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| redhat build of apache camel - hawtio | 4.0 |
CPE
Remediation
| |
| redhat build of apache camel for spring boot | 4.0 |
CPE
Remediation
| |
| redhat data grid | 8.0 |
CPE
Remediation
| |
| redhat fuse | 7.0.0 |
CPE
Remediation
| |
| redhat jboss enterprise application platform | 7.0.0 8.0.0 |
CPE
Remediation
| |
| redhat jboss enterprise application platform expansion pack | All versions |
CPE
Remediation
| |
| redhat process automation | 7.0 |
CPE
Remediation
| |
| redhat single sign-on | 7.0 |
CPE
Remediation
| |
| redhat undertow | All versions |
CPE
Remediation
| |
| redhat enterprise linux | 9.0 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 21, 2026 | CVE Modified | [email protected] |
| Jul 22, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 10, 2026 | CVE Modified | [email protected] |
| Mar 31, 2026 | Initial Analysis | [email protected] |
| Mar 27, 2026 | New CVE Received | [email protected] |