Undertow是美国Undertow公司的一个Web服务器。 Undertow存在环境问题漏洞,该漏洞源于处理以空格开头的HTTP请求头时违反标准,可能导致远程攻击者执行请求夹带攻击,从而绕过安全机制或访问受限信息。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat build of Apache Camel - HawtIO 4 | any |
unaffected |
| Red Hat | Red Hat build of Apache Camel for Spring Boot 4 | any |
affected |
| Red Hat | Red Hat Data Grid 8 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 10 | any |
unaffected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
unaffected |
any |
unaffected | ||
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
| Red Hat | Red Hat Fuse 7 | any |
affected |
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 | any |
affected |
| Red Hat | Red Hat JBoss Enterprise Application Platform 8 | any |
affected |
any |
affected | ||
| Red Hat | Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8 | 0:2.40.0-7.redhat_00015.1.el8eap< * |
unaffected |
0:801.6.1-1.GA_redhat_00001.1.el8eap< * |
unaffected | ||
0:2.3.24-3.SP2_redhat_00001.1.el8eap< * |
unaffected | ||
0:8.1.6-7.GA_redhat_00010.1.el8eap< * |
unaffected | ||
| Red Hat | Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9 | 0:2.40.0-7.redhat_00015.1.el9eap< * |
unaffected |
0:801.6.1-1.GA_redhat_00001.1.el9eap< * |
unaffected | ||
0:2.3.24-3.SP2_redhat_00001.1.el9eap< * |
unaffected | ||
0:8.1.6-7.GA_redhat_00010.1.el9eap< * |
unaffected | ||
| Red Hat | Red Hat JBoss Enterprise Application Platform 8.1.7.GA | 2.3.24.SP3-redhat-00001< * |
unaffected |
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | any |
affected |
any |
affected | ||
any |
unaffected | ||
| Red Hat | Red Hat Process Automation 7 | any |
affected |
| Red Hat | Red Hat Single Sign-On 7 | any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat JBoss Enterprise Application Platform 8.1.7.GA | 2.3.24.SP3-redhat-00001 ~ * |
cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el9
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8 | 0:2.40.0-7.redhat_00015.1.el8eap ~ * |
cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el8
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8 | 0:801.6.1-1.GA_redhat_00001.1.el8eap ~ * |
cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el8
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8 | 0:2.3.24-3.SP2_redhat_00001.1.el8eap ~ * |
cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el8
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8 | 0:8.1.6-7.GA_redhat_00010.1.el8eap ~ * |
cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el8
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9 | 0:2.40.0-7.redhat_00015.1.el9eap ~ * |
cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el8
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9 | 0:801.6.1-1.GA_redhat_00001.1.el9eap ~ * |
cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el8
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9 | 0:2.3.24-3.SP2_redhat_00001.1.el9eap ~ * |
cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el8
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9 | 0:8.1.6-7.GA_redhat_00010.1.el9eap ~ * |
cpe:/a:redhat:jboss_enterprise_application_platform:8.1::el8
|
|
| Red Hat | Red Hat build of Apache Camel for Spring Boot 4 | - |
cpe:/a:redhat:camel_spring_boot:4
|
|
| Red Hat | Red Hat build of Apache Camel - HawtIO 4 | - |
cpe:/a:redhat:apache_camel_hawtio:4
|
|
| Red Hat | Red Hat Data Grid 8 | - |
cpe:/a:redhat:jboss_data_grid:8
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Fuse 7 | - |
cpe:/a:redhat:jboss_fuse:7
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 | - |
cpe:/a:redhat:jboss_enterprise_application_platform:7
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform 8 | - |
cpe:/a:redhat:jboss_enterprise_application_platform:8
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform 8 | - |
cpe:/a:redhat:jboss_enterprise_application_platform:8
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | - |
cpe:/a:redhat:jbosseapxp
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | - |
cpe:/a:redhat:jbosseapxp
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | - |
cpe:/a:redhat:jbosseapxp
|
|
| Red Hat | Red Hat Process Automation 7 | - |
cpe:/a:redhat:jboss_enterprise_bpms_platform:7
|
|
| Red Hat | Red Hat Single Sign-On 7 | - |
cpe:/a:redhat:red_hat_single_sign_on:7
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-28368 | 8.7 HIGH | Undertow: undertow: request smuggling via inconsistent header parsing |
| CVE-2026-28367 | 8.7 HIGH | Undertow: undertow: request smuggling via `\r\r\r` as a header block terminator |
| CVE-2026-4948 | 5.5 MEDIUM | Firewalld: firewalld: local unprivileged user can modify firewall state due to d-bus sette |
No comments yet