CVE-2017-12165: Red Hat JBoss Enterprise Application Platform

High severity, CVSS 7.5. EPSS: 1.9% chance of exploitation in the next 30 days.

It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces which can cause possible http request smuggling.

Affected products

  • Red Hat JBoss Enterprise Application Platform: version 7.0.0 only; version 7.1.0 only
  • Red Hat Undertow: from 1.0.0, before 1.3.31 (fixed in 1.3.31); from 1.4.0, before 1.4.17 (fixed in 1.4.17); version 2.0.0 only

Published 2018-07-27. Last modified 2026-06-17.