#1134951 undertow: CVE-2026-28368

Package:
src:undertow
Source:
src:undertow
Submitter:
Moritz Mühlenhoff
Date:
2026-04-26 11:53:02 UTC
Severity:
normal
Tags:
#1134951#5
Date:
2026-04-26 11:16:30 UTC
From:
To:
Hi,

The following vulnerability was published for undertow.

CVE-2026-28368[0]:
| A flaw was found in Undertow. This vulnerability allows a remote
| attacker to construct specially crafted requests where header names
| are parsed differently by Undertow compared to upstream proxies.
| This discrepancy in header interpretation can be exploited to launch
| request smuggling attacks, potentially bypassing security controls
| and accessing unauthorized resources.

https://bugzilla.redhat.com/show_bug.cgi?id=2443261


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-28368
https://www.cve.org/CVERecord?id=CVE-2026-28368

Please adjust the affected versions in the BTS as needed.