CVE-2018-1067: Red Hat JBoss Enterprise Application Platform

Medium severity, CVSS 6.1. EPSS: 1.8% chance of exploitation in the next 30 days.

In Undertow before versions 7.1.2.CR1, 7.1.2.GA it was found that the fix for CVE-2016-4993 was incomplete and Undertow web server is vulnerable to the injection of arbitrary HTTP headers, and also response splitting, due to insufficient sanitization and validation of user input before the input is used as part of an HTTP header value.

Affected products

  • Red Hat JBoss Enterprise Application Platform: version 7.1 only
  • Red Hat Undertow: before 1.4.25 (fixed in 1.4.25); from 2.0.0, before 2.0.5 (fixed in 2.0.5)
  • Red Hat Virtualization Host: version 4.0 only

Published 2018-05-21. Last modified 2026-06-17.