CVE-2026-28369 - Vulnerability Analysis
HighCVSS: 8.7Last Updated: March 27, 2026
Undertow - HTTP Request Smuggling
Published: March 27, 2026Updated: March 27, 2026Remote Exploitable
Overview
Undertow contains an HTTP request smuggling vulnerability caused by incorrect processing of header lines starting with spaces, letting remote attackers bypass security and manipulate requests, exploit requires crafted HTTP requests.
Severity & Score
Severity: High
CVSS Score: 8.7
Impact
Remote attackers can bypass security controls, access restricted data, or manipulate web caches, leading to unauthorized actions or data exposure.
Mitigation
Update to the latest version of Undertow.
References
Related Resources
Details
- CVE ID
- CVE-2026-28369
- Severity
- High
- CVSS Score
- 8.7
- Type
- http_request_smuggling
- Status
- new
CWE
- CWE-444
CVSS Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N