CVE-2026-28369 identifies a critical flaw in Undertow, impacting various Red Hat products including JBoss EAP and Enterprise Linux, where it incorrectly processes HTTP requests with leading spaces in the first header line. This misinterpretation allows a remote attacker to perform request smuggling, bypassing security mechanisms and potentially leading to unauthorized information access or data manipulation. The vulnerability carries a CVSS score of 9.1 (CRITICAL) due to its network attack vector, low attack complexity, and high impact on confidentiality and integrity. While severe, there is currently no evidence of active exploitation, no public exploit code available, and it is not listed on the CISA KEV catalog, though it has received some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0CPE matchmatch criteria | cpe:2.3:a:redhat:build_of_apache_camel_-_hawtio:4.0:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:a:redhat:build_of_apache_camel_for_spring_boot:4.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:a:redhat:data_grid:8.0:*:*:*:*:*:*:* | ||
7.0.0CPE matchmatch criteria | cpe:2.3:a:redhat:fuse:7.0.0:*:*:*:*:*:*:* | ||
7.0.0CPE matchmatch criteria | cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.