Description

A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header interpretation can be exploited to launch request smuggling attacks, potentially bypassing security controls and accessing unauthorized resources.

INFO

Published Date :

2026-03-27T16:13:03.775Z

Last Modified :

2026-03-27T19:57:36.565Z

Source :

redhat
AFFECTED PRODUCTS

The following products are affected by CVE-2026-28368 vulnerability.

Vendors Products
Redhat
  • Apache Camel Hawtio
  • Camel Spring Boot
  • Enterprise Linux
  • Jboss Data Grid
  • Jboss Enterprise Application Platform
  • Jboss Enterprise Bpms Platform
  • Jboss Fuse
  • Jbosseapxp
  • Red Hat Single Sign On
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2026-28368.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact