A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containing malformed or malicious Host headers are processed without rejection, enabling attackers to poison caches, perform internal network scans, or hijack user sessions.
The Undertow server, used among others in WildFly, JBoss EAP and other Java applications, does not reject HTTP requests containing distorted or malicious Host header values. An attacker can craft a request with a manipulated Host header, which will be processed by the server without verification. This leads to the possibility of executing Host Header Injection attacks, including cache poisoning, scanning of internal network resources (SSRF), and interception of user sessions.
An attacker may poison the server or network intermediary cache, conduct scanning of internal network resources, or hijack sessions of logged-in users, which may lead to violation of data confidentiality and integrity.
Patches available from the vendor should be applied according to the errata: RHSA-2026:0383, RHSA-2026:0384, RHSA-2026:0386, RHSA-2026:3889, RHSA-2026:3890 published by Red Hat
Red Hat Build of Apache Camel, Red Hat Data Grid, Red Hat Fuse, Red Hat JBoss Enterprise Application Platform — versions indicated in vendor references
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:LRed Hat Build Of Apache Camel
APPRedhat< 4.14.4Red Hat Data Grid
APPRedhat8.0Red Hat Fuse
APPRedhat7.0.0Red Hat Jboss Enterprise Application Platform
APPRedhat7.0.08.1.0 – 8.1.3 (excl.)8.0 – 8.0.12 (excl.)Red Hat Jboss Enterprise Application Platform Expansion Pack
APPRedhatall versionsRed Hat Process Automation
APPRedhat7.0Red Hat Single Sign On
APPRedhat7.0Red Hat Undertow
APPRedhat< 2.2.392.3.0 – 2.3.21 (excl.)
Related vulnerabilities
RCE przez niebezpieczną deserializację w JBoss HTTP Invoker (EAP 5.2)
Apache Shiro RCE przez nieskonfigurowany klucz szyfrowania 'remember me'
Elasticsearch: ucieczka z sandboksa Groovy i zdalne wykonanie poleceń
XSS w Keycloak — podatność w obsłudze SAML/OIDC umożliwia wykonanie złośliwych skryptów
Pominięcie uwierzytelnienia REST w Red Hat DataGrid i Infinispan