product of redhat
undertow
Severity
Being told
The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.
Every thing
| undertow: Undertow: Request Smuggling via Malformed HTTP Request Headers CVE-2026-28369 | Severity critical |
| undertow: Undertow: Request smuggling via inconsistent header parsing CVE-2026-28368 | Severity critical |
| undertow: Undertow: Request smuggling via `\r\r\r` as a header block terminator CVE-2026-28367 | Severity critical |
| undertow-core: Undertow HTTP Server Fails to Reject Malformed Host Headers Leading to Potential Cache Poisoning and SSRF CVE-2025-12543 | Severity critical |
| undertow: Undertow MadeYouReset HTTP/2 DDoS Vulnerability CVE-2025-9784 | Severity high |