Junglewise Threat Intelligence

CVE-2026-28367: Red Hat Undertow request smuggling via malformed header terminator

CVE-2026-28367 · Severity: high · CVSS 8.7 · Published 2026-03-27

Technologies: io.undertow:undertow-parent (Maven). Vendors: Red Hat, Maven.

Executive brief

Undertow, a high-performance web server used in many Java applications, is vulnerable to a flaw that allows attackers to manipulate how web requests are processed. By sending specially crafted data, an attacker can 'smuggle' hidden requests past security filters or load balancers, potentially leading to unauthorized access to sensitive data or the ability to bypass security controls. This issue primarily affects environments using specific proxy servers like older versions of Apache Traffic Server or Google Cloud Load Balancers.

Technical details

A request smuggling vulnerability (CWE-444) exists in Undertow due to inconsistent interpretation of HTTP request headers. Specifically, Undertow incorrectly allows the byte sequence `\r\r\r` to act as a header block terminator. When Undertow is deployed behind certain proxy servers or load balancers (such as older versions of Apache Traffic Server or Google Cloud Classic Application Load Balancer) that do not recognize this sequence as a terminator, an attacker can craft a request that is interpreted differently by the proxy and the backend server. This allows the attacker to 'smuggle' a second, hidden request inside the first one, leading to potential credential hijacking, security filter bypass, or unauthorized data access. The vulnerability is patched in Undertow 2.3.24.SP2 and incorporated into Red Hat JBoss EAP 8.1.6.

Affected products

  • Red Hat Undertow <= 2.3.23.Final
  • Red Hat JBoss Enterprise Application Platform 8.1

Timeline

  • 2026-02-27: disclosed: Initial report in Red Hat Bugzilla
  • 2026-03-27: advisory: GitHub and NVD advisory published
  • 2026-06-10: patched: Red Hat released security updates (RHSA-2026:25125, RHSA-2026:25126)

References

Related threats