Undertow Request Smuggling vulnerability
High severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Mar 20, 2024
Package
Affected versions
< 1.3.31
>= 1.4.0, < 1.4.17
= 2.0.0.Alpha1
Patched versions
1.3.31
1.4.17
2.0.0.Beta1
Description
Published by the National Vulnerability Database
Jul 27, 2018
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Nov 8, 2022
Last updated
Mar 20, 2024
It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces which can cause possible http request smuggling.
References