CVE-2026-28368 - Vulnerability Analysis
HighCVSS: 8.7Last Updated: March 30, 2026
Undertow - HTTP Request Smuggling
Overview
Undertow contains an HTTP request smuggling vulnerability caused by inconsistent header name parsing compared to upstream proxies, letting remote attackers bypass security controls and access unauthorized resources, exploit requires crafted requests.
Severity & Score
Impact
Remote attackers can bypass security controls and access unauthorized resources via request smuggling.
Mitigation
Update to the latest version of Undertow.
References
Social Media Activity(1 post)
š CVE-2026-28368 - High (8.7) A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header interpretation can be ... š https://www.thehackerwire.com/vulnerability/CVE-2026-28368/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postRelated Resources
Details
- CVE ID
- CVE-2026-28368
- Severity
- High
- CVSS Score
- 8.7
- Type
- http_request_smuggling
- Status
- unconfirmed
- EPSS
- 9.5%
- Social Posts
- 1
CWE
- CWE-444
CVSS Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N