Loading
A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header interpretation can be exploited to launch request smuggling attacks, potentially bypassing security controls and accessing unauthorized resources.
Use CWE-444, Redhat vendor hub and Build Of Apache Camel - Hawtio product page to widen CVE-2026-28368 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-28369, CVE-2026-28367 and CVE-2024-7885 for nearby disclosures in the same product family.