Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-19879— Io.undertow/undertow: undertow: http response header integrity issue due to character truncation

Quick assessment

Affected
Red Hat Red Hat build of Apache Camel for Spring Boot 4
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Undertow是美国Undertow组织开源的个灵活高效的 Java Web 服务器。 Undertow存在数字错误漏洞,该漏洞源于writeString()方法在写入HTTP响应头时将16位Unicode字符静默转换为8位字节,导致字符截断为ASCII控制字符或特殊符号,可能造成有限完整性影响或信息泄露。

CVSS 5.3 · Medium EPSS 0.39% · P31

Possible ATT&CK Techniques 1 AI

T1505 · Server Software Component

Affected Version Matrix 24

VendorProduct Version RangeStatus
Red Hat Red Hat build of Apache Camel for Spring Boot 4 any affected
any affected
any affected
any affected
Red Hat Red Hat Enterprise Linux 10 any affected
Red Hat Red Hat Enterprise Linux 8 any affected
any affected
Red Hat Red Hat Enterprise Linux 9 any affected
Red Hat Red Hat JBoss Enterprise Application Platform 7 any affected
any affected
any affected
any affected
any affected
any affected
any affected
Red Hat Red Hat JBoss Enterprise Application Platform 8 any affected
any affected
any affected
Red Hat Red Hat JBoss Enterprise Application Platform Expansion Pack any affected
any affected
any affected
Red Hat Red Hat Single Sign-On 7 any affected
any affected
any affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-19879

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Io.undertow/undertow: undertow: http response header integrity issue due to character truncation
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in Undertow, an HTTP server, within its HTTP response header writing path. The `writeString()` method performs a silent narrowing cast from 16-bit Unicode characters to 8-bit bytes when writing HTTP response header values. A remote attacker can exploit this by supplying specific Unicode characters in user-controlled input that an application places into response headers. This can lead to the truncation of these characters into ASCII control characters or special symbols, potentially resulting in limited integrity impact or information disclosure if the application does not properly sanitize user input.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
数值类型间的不正确转换
Source: CVE Program / CVE List V5
Vulnerability Title
Undertow 数字错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Undertow是美国Undertow组织开源的个灵活高效的 Java Web 服务器。 Undertow存在数字错误漏洞,该漏洞源于writeString()方法在写入HTTP响应头时将16位Unicode字符静默转换为8位字节,导致字符截断为ASCII控制字符或特殊符号,可能造成有限完整性影响或信息泄露。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat build of Apache Camel for Spring Boot 4 - cpe:/a:redhat:camel_spring_boot:4
Red Hat Red Hat build of Apache Camel for Spring Boot 4 - cpe:/a:redhat:camel_spring_boot:4
Red Hat Red Hat build of Apache Camel for Spring Boot 4 - cpe:/a:redhat:camel_spring_boot:4
Red Hat Red Hat build of Apache Camel for Spring Boot 4 - cpe:/a:redhat:camel_spring_boot:4
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9
Red Hat Red Hat JBoss Enterprise Application Platform 7 - cpe:/a:redhat:jboss_enterprise_application_platform:7
Red Hat Red Hat JBoss Enterprise Application Platform 7 - cpe:/a:redhat:jboss_enterprise_application_platform:7
Red Hat Red Hat JBoss Enterprise Application Platform 7 - cpe:/a:redhat:jboss_enterprise_application_platform:7
Red Hat Red Hat JBoss Enterprise Application Platform 7 - cpe:/a:redhat:jboss_enterprise_application_platform:7
Red Hat Red Hat JBoss Enterprise Application Platform 7 - cpe:/a:redhat:jboss_enterprise_application_platform:7
Red Hat Red Hat JBoss Enterprise Application Platform 7 - cpe:/a:redhat:jboss_enterprise_application_platform:7
Red Hat Red Hat JBoss Enterprise Application Platform 7 - cpe:/a:redhat:jboss_enterprise_application_platform:7
Red Hat Red Hat JBoss Enterprise Application Platform 8 - cpe:/a:redhat:jboss_enterprise_application_platform:8
Red Hat Red Hat JBoss Enterprise Application Platform 8 - cpe:/a:redhat:jboss_enterprise_application_platform:8
Red Hat Red Hat JBoss Enterprise Application Platform 8 - cpe:/a:redhat:jboss_enterprise_application_platform:8
Red Hat Red Hat JBoss Enterprise Application Platform Expansion Pack - cpe:/a:redhat:jbosseapxp
Red Hat Red Hat JBoss Enterprise Application Platform Expansion Pack - cpe:/a:redhat:jbosseapxp
Red Hat Red Hat JBoss Enterprise Application Platform Expansion Pack - cpe:/a:redhat:jbosseapxp
Red Hat Red Hat Single Sign-On 7 - cpe:/a:redhat:red_hat_single_sign_on:7
Red Hat Red Hat Single Sign-On 7 - cpe:/a:redhat:red_hat_single_sign_on:7
Red Hat Red Hat Single Sign-On 7 - cpe:/a:redhat:red_hat_single_sign_on:7

II. Public POCs for CVE-2026-19879

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-19879

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-19879 (2)

Same Patch Batch · Red Hat · 2026-08-14 · 11 CVEs total

CVE-2026-58224 6.5 MEDIUM Samba: ctdb fails to do integrity checking of received packets
CVE-2026-74243 6.5 MEDIUM Quay: unauthenticated secscan notification endpoint in quay when psk is unset
CVE-2026-74244 5.9 MEDIUM Quay: stripe webhook accepts forged events without signature verification in quay
CVE-2026-74245 5.9 MEDIUM Quay: unauthenticated exported logs download in quay
CVE-2026-19617 5.5 MEDIUM Libdm: lvm2: libdm: denial of service via uncontrolled recursion in config parser
CVE-2026-74240 5.4 MEDIUM Quay: jwt claim validation bypasses in quay federated robot and sso authentication
CVE-2026-74242 5.3 MEDIUM Quay: repository notification uuid idor in quay api
CVE-2026-74241 4.8 MEDIUM Quay: ldap referral filter injection in quay external ldap authentication
CVE-2026-13002 4.4 MEDIUM Dnsmasq: infinite loop dos in dnssec nsec/nsec3 type bitmap parsing
CVE-2026-74247 4.2 MEDIUM Quay: ssrf via build archive_url in quay build api

IV. Related Vulnerabilities

V. Comments for CVE-2026-19879

No comments yet


Leave a comment