CVE-2026-28368: Undertow: undertow: request smuggling via inconsistent header parsing
Published Feb 27, 2026
·Updated
A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header interpretation can be exploited to launch request smuggling attacks, potentially bypassing security controls and accessing unauthorized resources.
Other sources
Undertow splits header names from values on either space or colon, whichever comes first. This allows for the construction of crafted requests with headers that are visible only to Undertow, but not upstream proxies, which can be used to launch request smuggling attacks.
— Red Hat
Affected Software
12 affected components
Red Hat Undertow
redhat Build Of Apache Camel - Hawtio=4.0
redhat Build Of Apache Camel For Spring Boot=4.0
redhat Data Grid=8.0
redhat Fuse=7.0.0
redhat JBoss Enterprise Application Platform=7.0.0
redhat JBoss Enterprise Application Platform=8.0.0
redhat Jboss Enterprise Application Platform Expansion Pack
redhat Process Automation=7.0
redhat Single Sign-on=7.0
redhat undertow
redhat Enterprise Linux=9.0
Event History
Feb 27, 2026
Data Sourced
via Red Hat·04:44 AM
DescriptionSeverityAffected Software
Mar 27, 2026
CVE Published
via MITRE·04:13 PM
Data Sourced
via MITRE·04:13 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software