CVE-2026-19879: Io.undertow/undertow: undertow: http response header integrity issue due to character truncation

Published Aug 14, 2026
·
Updated

A flaw was found in Undertow, an HTTP server, within its HTTP response header writing path. The writeString() method performs a silent narrowing cast from 16-bit Unicode characters to 8-bit bytes when writing HTTP response header values. A remote attacker can exploit this by supplying specific Unicode characters in user-controlled input that an application places into response headers. This can lead to the truncation of these characters into ASCII control characters or special symbols, potentially resulting in limited integrity impact or information disclosure if the application does not properly sanitize user input.

Affected Software

1 affected component
Io.undertow/undertow

Event History

Aug 14, 2026
Data Sourced
via Red Hat·02:30 PM
DescriptionSeverityAffected Software
CVE Published
via MITRE·02:51 PM
Data Sourced
via MITRE·02:51 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-19879?

CVE-2026-19879 has a medium severity rating of 5.3.

2

How does CVE-2026-19879 affect the Undertow HTTP server?

CVE-2026-19879 affects the Undertow HTTP server by introducing an integrity issue in the HTTP response header writing path.

3

What kind of attack can be executed using CVE-2026-19879?

A remote attacker can exploit CVE-2026-19879 by supplying specific Unicode characters to manipulate HTTP response headers.

4

How can I mitigate the risks associated with CVE-2026-19879?

To mitigate the risks of CVE-2026-19879, it is recommended to update to the latest version of the Undertow software.

5

What is the root cause of the issue in CVE-2026-19879?

The root cause of CVE-2026-19879 is a silent narrowing cast from 16-bit Unicode characters to 8-bit bytes in the writeString() method.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203