Description

A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, which violates HTTP standards, can be exploited by a remote attacker to perform request smuggling. Request smuggling allows an attacker to bypass security mechanisms, access restricted information, or manipulate web caches, potentially leading to unauthorized actions or data exposure.

INFO

Published Date :

2026-03-27T16:13:05.719Z

Last Modified :

2026-03-30T02:31:22.322Z

Source :

redhat
AFFECTED PRODUCTS

The following products are affected by CVE-2026-28369 vulnerability.

Vendors Products
Redhat
  • Apache Camel Hawtio
  • Camel Spring Boot
  • Enterprise Linux
  • Jboss Data Grid
  • Jboss Enterprise Application Platform
  • Jboss Enterprise Bpms Platform
  • Jboss Fuse
  • Jbosseapxp
  • Red Hat Single Sign On
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2026-28369.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact