Undertow: undertow: request smuggling via malformed http request headers
Published Mar 27, 2026
9.1
CRITICALCVSS 3.1
EPSS 0.89%
Description
A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, which violates HTTP standards, can be exploited by a remote attacker to perform request smuggling. Request smuggling allows an attacker to bypass security mechanisms, access restricted information, or manipulate web caches, potentially leading to unauthorized actions or data exposure.
Affected products
-
-
-
-
-
- Vendor Red Hat Product Red Hat JBoss Enterprise Application Platform Expansion Pack Defaultaffected
-
-
-
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat Data Grid 8 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 9 | affected |
| |||
| Red Hat | Red Hat Fuse 7 | affected |
| |||
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 | affected |
| |||
| Red Hat | Red Hat JBoss Enterprise Application Platform 8 | affected |
| |||
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | affected |
| |||
| Red Hat | Red Hat Process Automation 7 | affected |
| |||
| Red Hat | Red Hat Single Sign-On 7 | affected |
| |||
| Red Hat | Red Hat build of Apache Camel for Spring Boot 4 | affected |
|
- 4.0
- 4.0
- 8.0
- 7.0.0
- 7.0.0
- 8.0.0
- n/a
- 7.0
- 7.0
- n/a
- 9.0
No data.
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8
eap8-activemq-artemis-0:2.40.0-7.redhat_00015.1.el8eap
Fixed · RHSA-2026:25125
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8
eap8-eap-product-conf-parent-0:801.6.1-1.GA_redhat_00001.1.el8eap
Fixed · RHSA-2026:25125
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8
eap8-undertow-0:2.3.24-3.SP2_redhat_00001.1.el8eap
Fixed · RHSA-2026:25125
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8
eap8-wildfly-0:8.1.6-7.GA_redhat_00010.1.el8eap
Fixed · RHSA-2026:25125
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9
eap8-activemq-artemis-0:2.40.0-7.redhat_00015.1.el9eap
Fixed · RHSA-2026:25125
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9
eap8-eap-product-conf-parent-0:801.6.1-1.GA_redhat_00001.1.el9eap
Fixed · RHSA-2026:25125
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9
eap8-undertow-0:2.3.24-3.SP2_redhat_00001.1.el9eap
Fixed · RHSA-2026:25125
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9
eap8-wildfly-0:8.1.6-7.GA_redhat_00010.1.el9eap
Fixed · RHSA-2026:25125
Red Hat JBoss Enterprise Application Platform 8.1.7.GA
io.undertow/undertow-core:2.3.24.SP3-redhat-00001
Fixed · RHSA-2026:25126
Red Hat Data Grid 8
undertow-core
Will not fix
Red Hat Enterprise Linux 10
moditect
Not affected
Red Hat Enterprise Linux 8
pki-core:10.6/resteasy
Not affected
Red Hat Enterprise Linux 8
pki-deps:10.6/resteasy
Not affected
Red Hat Enterprise Linux 9
resteasy
Affected
Red Hat Fuse 7
undertow-core
Will not fix
Red Hat JBoss Enterprise Application Platform 7
undertow-core
Will not fix
Red Hat JBoss Enterprise Application Platform 8
org.jberet-jberet-parent
Affected
Red Hat JBoss Enterprise Application Platform 8
undertow-core
Affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
org.jberet-jberet-parent
Affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
org.jboss.eap-jboss-eap-xp
Affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
undertow-core
Not affected
Red Hat Process Automation 7
undertow-core
Will not fix
Red Hat Single Sign-On 7
undertow-core
Fix deferred
Red Hat build of Apache Camel - HawtIO 4
undertow-core
Not affected
Red Hat build of Apache Camel for Spring Boot 4
undertow-core
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8 | eap8-activemq-artemis-0:2.40.0-7.redhat_00015.1.el8eap | Fixed | RHSA-2026:25125 |
| Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8 | eap8-eap-product-conf-parent-0:801.6.1-1.GA_redhat_00001.1.el8eap | Fixed | RHSA-2026:25125 |
| Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8 | eap8-undertow-0:2.3.24-3.SP2_redhat_00001.1.el8eap | Fixed | RHSA-2026:25125 |
| Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8 | eap8-wildfly-0:8.1.6-7.GA_redhat_00010.1.el8eap | Fixed | RHSA-2026:25125 |
| Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9 | eap8-activemq-artemis-0:2.40.0-7.redhat_00015.1.el9eap | Fixed | RHSA-2026:25125 |
| Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9 | eap8-eap-product-conf-parent-0:801.6.1-1.GA_redhat_00001.1.el9eap | Fixed | RHSA-2026:25125 |
| Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9 | eap8-undertow-0:2.3.24-3.SP2_redhat_00001.1.el9eap | Fixed | RHSA-2026:25125 |
| Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9 | eap8-wildfly-0:8.1.6-7.GA_redhat_00010.1.el9eap | Fixed | RHSA-2026:25125 |
| Red Hat JBoss Enterprise Application Platform 8.1.7.GA | io.undertow/undertow-core:2.3.24.SP3-redhat-00001 | Fixed | RHSA-2026:25126 |
| Red Hat Data Grid 8 | undertow-core | Will not fix | n/a |
| Red Hat Enterprise Linux 10 | moditect | Not affected | n/a |
| Red Hat Enterprise Linux 8 | pki-core:10.6/resteasy | Not affected | n/a |
| Red Hat Enterprise Linux 8 | pki-deps:10.6/resteasy | Not affected | n/a |
| Red Hat Enterprise Linux 9 | resteasy | Affected | n/a |
| Red Hat Fuse 7 | undertow-core | Will not fix | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | undertow-core | Will not fix | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | org.jberet-jberet-parent | Affected | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | undertow-core | Affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | org.jberet-jberet-parent | Affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | org.jboss.eap-jboss-eap-xp | Affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | undertow-core | Not affected | n/a |
| Red Hat Process Automation 7 | undertow-core | Will not fix | n/a |
| Red Hat Single Sign-On 7 | undertow-core | Fix deferred | n/a |
| Red Hat build of Apache Camel - HawtIO 4 | undertow-core | Not affected | n/a |
| Red Hat build of Apache Camel for Spring Boot 4 | undertow-core | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
1 other source (GHSA) ▾
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Mar 28, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Mar–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.89% (0.00886) | 57.78th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.68% (0.00677) | 47.26th | v5 (v2026.06.15) |
| Mar 28, 2026 | 0.13% (0.00129) | 32.37th | v4 (v2025.03.14) |
References (7)
- https://access.redhat.com/errata/RHSA-2026:25125 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:25126 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2026-28369 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2443262 issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory
- https://github.com/advisories/GHSA-vqqj-9cmv-hx43 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-28369
- https://www.cve.org/CVERecord?id=CVE-2026-28369
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:25125 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2026:25126 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2026-28369 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2443262 | issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory | |
| https://github.com/advisories/GHSA-vqqj-9cmv-hx43 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-28369 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-28369 |
Change history (0)
No recorded changes yet.