A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certain proxy servers, such as older versions of Apache Traffic Server and Google Cloud Classic Application Load Balancer, potentially leading to unauthorized access or manipulation of web requests.
References
| Link | Resource |
|---|---|
| https://access.redhat.com/security/cve/CVE-2026-28367 | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2443260 | Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
10 Apr 2026, 14:22
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:redhat:undertow:-:*:*:*:*:*:*:* cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.0.0:*:*:*:*:*:*:* cpe:2.3:a:redhat:build_of_apache_camel_-_hawtio:4.0:*:*:*:*:*:*:* cpe:2.3:a:redhat:fuse:7.0.0:*:*:*:*:*:*:* cpe:2.3:a:redhat:data_grid:8.0:*:*:*:*:*:*:* cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:* cpe:2.3:a:redhat:jboss_enterprise_application_platform:8.0.0:*:*:*:*:*:*:* cpe:2.3:a:redhat:jboss_enterprise_application_platform_expansion_pack:-:*:*:*:*:*:*:* cpe:2.3:a:redhat:process_automation:7.0:*:*:*:*:*:*:* cpe:2.3:a:redhat:build_of_apache_camel_for_spring_boot:4.0:*:*:*:*:*:*:* |
|
| References | () https://access.redhat.com/security/cve/CVE-2026-28367 - Vendor Advisory | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=2443260 - Issue Tracking, Vendor Advisory | |
| First Time |
Redhat fuse
Redhat jboss Enterprise Application Platform Expansion Pack Redhat data Grid Redhat build Of Apache Camel - Hawtio Redhat Redhat process Automation Redhat jboss Enterprise Application Platform Redhat single Sign-on Redhat undertow Redhat build Of Apache Camel For Spring Boot |
27 Mar 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-27 17:16
Updated : 2026-04-10 14:22
NVD link : CVE-2026-28367
Mitre link : CVE-2026-28367
CVE.ORG link : CVE-2026-28367
JSON object : View
Products Affected
redhat
- single_sign-on
- build_of_apache_camel_for_spring_boot
- jboss_enterprise_application_platform
- undertow
- build_of_apache_camel_-_hawtio
- jboss_enterprise_application_platform_expansion_pack
- process_automation
- data_grid
- fuse
CWE
CWE-444
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
