CVE-2017-12165: Red Hat JBoss Enterprise Application Platform
High severity, CVSS 7.5. EPSS: 1.9% chance of exploitation in the next 30 days.
It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces which can cause possible http request smuggling.
Affected products
- Red Hat JBoss Enterprise Application Platform: version 7.0.0 only; version 7.1.0 only
- Red Hat Undertow: from 1.0.0, before 1.3.31 (fixed in 1.3.31); from 1.4.0, before 1.4.17 (fixed in 1.4.17); version 2.0.0 only
Published 2018-07-27. Last modified 2026-06-17.