It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces which can cause possible http request smuggling.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| io.undertow:undertow-core(Maven) | 0 | 1.3.31 | N/A |
| io.undertow:undertow-core(Maven) | 1.4.0 | 1.4.17 | N/A |
| io.undertow:undertow-core(Maven) | 2.0.0.Alpha1 | 2.0.0.Beta1 | N/A |
CVSS Metrics