An Improper Input Validation vulnerability exists in the Undertow HTTP server (io.undertow:undertow-core) where the implementation does not return a 400 Bad Request response when receiving requests with invalid or malformed Host headers. The flaw can be exploited by remote attackers via specially crafted HTTP requests. Depending on the deployment, the issue enables web cache poisoning, session hijacking, or server-side request forgery (SSRF). Attackers may inject malicious responses into caches, steal authentication tokens, or redirect users to malicious endpoints. Successful exploitation can result in complete account takeover, widespread credential theft, or unauthorized access to internal network resources, thereby compromising confidentiality and integrity of user data.
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 8.1 Via RHSA-2026:0386 https://access.redhat.com/errata/RHSA-2026:0386
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8 Via RHSA-2026:0383 https://access.redhat.com/errata/RHSA-2026:0383
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9 Via RHSA-2026:0384 https://access.redhat.com/errata/RHSA-2026:0384
This issue has been addressed in the following products: Red Hat build of Apache Camel 4.14.4 for Spring Boot 3.5.11 Via RHSA-2026:3890 https://access.redhat.com/errata/RHSA-2026:3890
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 8.0 Via RHSA-2026:3892 https://access.redhat.com/errata/RHSA-2026:3892
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 Via RHSA-2026:3891 https://access.redhat.com/errata/RHSA-2026:3891
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 Via RHSA-2026:3889 https://access.redhat.com/errata/RHSA-2026:3889
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 Via RHSA-2026:4915 https://access.redhat.com/errata/RHSA-2026:4915
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8 Via RHSA-2026:4916 https://access.redhat.com/errata/RHSA-2026:4916
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9 Via RHSA-2026:4917 https://access.redhat.com/errata/RHSA-2026:4917
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 Via RHSA-2026:4924 https://access.redhat.com/errata/RHSA-2026:4924