Executive brief
Undertow is a high-performance web server component used in major Java applications like WildFly and JBoss EAP. A security flaw has been identified where the server fails to properly check the 'Host' header in web requests. This could allow an attacker to trick the system into misrouting traffic, poisoning web caches, or gaining unauthorized access to internal network resources and user sessions.
Technical details
A flaw was found in the Undertow HTTP server core's input validation logic. The library fails to properly validate or reject malformed Host headers in incoming HTTP requests. An unauthenticated remote attacker can exploit this by sending specially crafted headers, which the server processes without rejection. This vulnerability can be leveraged to perform HTTP Cache Poisoning, Server-Side Request Forgery (SSRF) via internal network scans, or session hijacking. Red Hat has released updates for affected products, including JBoss EAP 8.1.3, which upgrades Undertow to version 2.3.20.SP4-redhat-00001 to resolve the issue.
Affected products
- Red Hat Undertow versions prior to 2.3.20.SP4-redhat-00001
- Red Hat JBoss Enterprise Application Platform (EAP) 8.1.x, 7.4.x
- Red Hat WildFly
- Red Hat Apache Camel for Spring Boot 4.14.x
Timeline
- 2025-01-07: disclosed: CVE published
- 2026-01-08: patched: Red Hat released security advisories (RHSA-2026:0383, RHSA-2026:0384)
References
- https://access.redhat.com/downloads/content/package-browser/
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html
- https://access.redhat.com/errata/RHSA-2026:0383
- https://access.redhat.com/errata/RHSA-2026:0384
- https://access.redhat.com/errata/RHSA-2026:0386
- https://access.redhat.com/errata/RHSA-2026:3889
- https://access.redhat.com/errata/RHSA-2026:3890