Red Hat disclosed two high-severity request smuggling vulnerabilities in Undertow, tracked as CVE-2026-28367 and CVE-2026-28368, that let remote attackers exploit parsing differences between Undertow and upstream proxies. Both issues are classified as CWE-444 and carry a CVSS v3.1 vector of AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N, indicating network-reachable attacks with high confidentiality and integrity impact.
CVE-2026-28367 allows attackers to use \r\r\r as a header block terminator to smuggle requests when Undertow sits behind certain proxy servers, with older versions of Apache Traffic Server and Google Cloud Classic Application Load Balancer specifically cited as exposed configurations. CVE-2026-28368 stems from inconsistent header-name parsing between Undertow and upstream proxies, creating another path to bypass security controls and reach unauthorized resources through crafted requests.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
On 2026-03-27, a second Undertow vulnerability, CVE-2026-28368, was reported. The issue stems from inconsistent header-name parsing between Undertow and upstream proxies, creating a request smuggling condition that could bypass security controls and expose unauthorized resources.
On 2026-03-27, Red Hat documented CVE-2026-28367 in Undertow. The flaw allows remote attackers to use `\r\r\r` as a header block terminator to trigger request smuggling behind certain proxies, including older Apache Traffic Server versions and Google Cloud Classic Application Load Balancer.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.