CVE-2026-28367 - Vulnerability Analysis
HighCVSS: 8.7Last Updated: March 27, 2026
Undertow - HTTP Request Smuggling
Published: March 27, 2026Updated: March 27, 2026Remote Exploitable
Overview
Undertow contains an HTTP request smuggling vulnerability caused by improper handling of header block terminators, letting remote attackers manipulate web requests, exploit requires sending '\r\r\r' as header terminator.
Severity & Score
Severity: High
CVSS Score: 8.7
Impact
Remote attackers can manipulate or gain unauthorized access to web requests, potentially bypassing security controls.
Mitigation
Update to the latest version of Undertow.
References
Related Resources
Details
- CVE ID
- CVE-2026-28367
- Severity
- High
- CVSS Score
- 8.7
- Type
- http_request_smuggling
- Status
- new
CWE
- CWE-444
CVSS Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N