Undertow: undertow: request smuggling via `\r\r\r` as a header block terminator
Published Mar 27, 2026
9.1
CRITICALCVSS 3.1
EPSS 0.89%
Description
A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certain proxy servers, such as older versions of Apache Traffic Server and Google Cloud Classic Application Load Balancer, potentially leading to unauthorized access or manipulation of web requests.
Affected products
-
-
-
-
- Vendor Red Hat Product Red Hat JBoss Enterprise Application Platform Expansion Pack Defaultaffected
-
-
-
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat Data Grid 8 | affected |
| |||
| Red Hat | Red Hat Fuse 7 | affected |
| |||
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 | affected |
| |||
| Red Hat | Red Hat JBoss Enterprise Application Platform 8 | affected |
| |||
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | affected |
| |||
| Red Hat | Red Hat Process Automation 7 | affected |
| |||
| Red Hat | Red Hat Single Sign-On 7 | affected |
| |||
| Red Hat | Red Hat build of Apache Camel for Spring Boot 4 | affected |
|
- 4.0
- 4.0
- 8.0
- 7.0.0
- 7.0.0
- 8.0.0
- n/a
- 7.0
- 7.0
- n/a
No data.
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8
eap8-activemq-artemis-0:2.40.0-7.redhat_00015.1.el8eap
Fixed · RHSA-2026:25125
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8
eap8-eap-product-conf-parent-0:801.6.1-1.GA_redhat_00001.1.el8eap
Fixed · RHSA-2026:25125
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8
eap8-undertow-0:2.3.24-3.SP2_redhat_00001.1.el8eap
Fixed · RHSA-2026:25125
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8
eap8-wildfly-0:8.1.6-7.GA_redhat_00010.1.el8eap
Fixed · RHSA-2026:25125
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9
eap8-activemq-artemis-0:2.40.0-7.redhat_00015.1.el9eap
Fixed · RHSA-2026:25125
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9
eap8-eap-product-conf-parent-0:801.6.1-1.GA_redhat_00001.1.el9eap
Fixed · RHSA-2026:25125
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9
eap8-undertow-0:2.3.24-3.SP2_redhat_00001.1.el9eap
Fixed · RHSA-2026:25125
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9
eap8-wildfly-0:8.1.6-7.GA_redhat_00010.1.el9eap
Fixed · RHSA-2026:25125
Red Hat JBoss Enterprise Application Platform 8.1.7.GA
io.undertow/undertow-core:2.3.24.SP3-redhat-00001
Fixed · RHSA-2026:25126
Red Hat Data Grid 8
undertow-core
Will not fix
Red Hat Enterprise Linux 10
moditect
Not affected
Red Hat Enterprise Linux 8
pki-core:10.6/resteasy
Not affected
Red Hat Enterprise Linux 8
pki-deps:10.6/resteasy
Not affected
Red Hat Enterprise Linux 9
resteasy
Not affected
Red Hat Fuse 7
undertow-core
Will not fix
Red Hat JBoss Enterprise Application Platform 7
undertow-core
Will not fix
Red Hat JBoss Enterprise Application Platform 8
org.jberet-jberet-parent
Affected
Red Hat JBoss Enterprise Application Platform 8
undertow-core
Affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
org.jberet-jberet-parent
Affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
org.jboss.eap-jboss-eap-xp
Affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
undertow-core
Not affected
Red Hat Process Automation 7
undertow-core
Will not fix
Red Hat Single Sign-On 7
undertow-core
Fix deferred
Red Hat build of Apache Camel - HawtIO 4
undertow-core
Not affected
Red Hat build of Apache Camel for Spring Boot 4
undertow-core
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8 | eap8-activemq-artemis-0:2.40.0-7.redhat_00015.1.el8eap | Fixed | RHSA-2026:25125 |
| Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8 | eap8-eap-product-conf-parent-0:801.6.1-1.GA_redhat_00001.1.el8eap | Fixed | RHSA-2026:25125 |
| Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8 | eap8-undertow-0:2.3.24-3.SP2_redhat_00001.1.el8eap | Fixed | RHSA-2026:25125 |
| Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8 | eap8-wildfly-0:8.1.6-7.GA_redhat_00010.1.el8eap | Fixed | RHSA-2026:25125 |
| Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9 | eap8-activemq-artemis-0:2.40.0-7.redhat_00015.1.el9eap | Fixed | RHSA-2026:25125 |
| Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9 | eap8-eap-product-conf-parent-0:801.6.1-1.GA_redhat_00001.1.el9eap | Fixed | RHSA-2026:25125 |
| Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9 | eap8-undertow-0:2.3.24-3.SP2_redhat_00001.1.el9eap | Fixed | RHSA-2026:25125 |
| Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9 | eap8-wildfly-0:8.1.6-7.GA_redhat_00010.1.el9eap | Fixed | RHSA-2026:25125 |
| Red Hat JBoss Enterprise Application Platform 8.1.7.GA | io.undertow/undertow-core:2.3.24.SP3-redhat-00001 | Fixed | RHSA-2026:25126 |
| Red Hat Data Grid 8 | undertow-core | Will not fix | n/a |
| Red Hat Enterprise Linux 10 | moditect | Not affected | n/a |
| Red Hat Enterprise Linux 8 | pki-core:10.6/resteasy | Not affected | n/a |
| Red Hat Enterprise Linux 8 | pki-deps:10.6/resteasy | Not affected | n/a |
| Red Hat Enterprise Linux 9 | resteasy | Not affected | n/a |
| Red Hat Fuse 7 | undertow-core | Will not fix | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | undertow-core | Will not fix | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | org.jberet-jberet-parent | Affected | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | undertow-core | Affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | org.jberet-jberet-parent | Affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | org.jboss.eap-jboss-eap-xp | Affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | undertow-core | Not affected | n/a |
| Red Hat Process Automation 7 | undertow-core | Will not fix | n/a |
| Red Hat Single Sign-On 7 | undertow-core | Fix deferred | n/a |
| Red Hat build of Apache Camel - HawtIO 4 | undertow-core | Not affected | n/a |
| Red Hat build of Apache Camel for Spring Boot 4 | undertow-core | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
To mitigate this vulnerability, configure any proxy servers positioned in front of Undertow to strictly validate HTTP header terminations. Ensure that these proxies are configured to reject or normalize non-standard header block terminators, such as `\r\r\r`, before forwarding requests to Undertow. This operational control helps prevent request smuggling attacks by ensuring that only properly formed HTTP requests reach the Undertow server.
Red Hat statement
The Undertow web server is susceptible to request smuggling when deployed with certain proxy servers that forward `\r\r\r` as a header block terminator. This flaw could enable an attacker to manipulate web requests, potentially leading to unauthorized access. Red Hat products using Undertow in environments with vulnerable proxy configurations, such as those found in older versions of Apache Traffic Server or Google Cloud Classic Application Load Balancer, are at risk.
Red Hat mitigation
To mitigate this vulnerability, configure any proxy servers positioned in front of Undertow to strictly validate HTTP header terminations. Ensure that these proxies are configured to reject or normalize non-standard header block terminators, such as `\r\r\r`, before forwarding requests to Undertow. This operational control helps prevent request smuggling attacks by ensuring that only properly formed HTTP requests reach the Undertow server.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
1 other source (GHSA) ▾
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Mar 31, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Mar–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.89% (0.00888) | 57.85th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.71% (0.00706) | 48.35th | v5 (v2026.06.15) |
| Mar 28, 2026 | 0.04% (0.00036) | 10.52th | v4 (v2025.03.14) |
References (7)
- https://access.redhat.com/errata/RHSA-2026:25125 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:25126 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2026-28367 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2443260 issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory
- https://github.com/advisories/GHSA-3gv6-g396-9v4r Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-28367
- https://www.cve.org/CVERecord?id=CVE-2026-28367
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:25125 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2026:25126 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2026-28367 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2443260 | issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory | |
| https://github.com/advisories/GHSA-3gv6-g396-9v4r | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-28367 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-28367 |
Change history (0)
No recorded changes yet.