
CVE-2026-28367 A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smugglin… https://www.cve.org/CVERecord?id=CVE-2026-28367
Post summary
The message discloses a new Undertow vulnerability (CVE‑2026‑28367) that allows request smuggling via a malicious header terminator sequence, but it provides no PoC, exploit code, or evidence of active exploitation.


