
🚨 Undertow Req Smuggling CVSS: 8.6 HTTP request smuggling in Undertow server leads to session hijacking. Exploits header parsing diffs for cache poisoning and cross-site request forgery. https://nvd.nist.gov/vuln/detail/CVE-2026-28369
Post summary
The tweet provides a concise technical overview of CVE‑2026‑28369, highlighting its impact and CVSS score, but it offers no PoC, exploit code, active exploitation evidence, or patch information.



