CVE-2017-12165 PUBLISHED

It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces which can cause possible http request smuggling.

EPSS 1.10% · 77.9th percentile

Risk Scores

EPSS Score
1.10%
77.9th percentile

Affected Products

VendorProductVersions
Ubuntu:25.10undertow2.3.18-2, 2.3.18-1, 0
Ubuntu:16.04:LTSundertow1.3.7-1, 1.3.11-1, 1.3.16-1
Ubuntu:24.04:LTSundertow0, 2.3.8-2
Ubuntu:20.04:LTSundertow0
Ubuntu:18.04:LTSundertow1.4.23-3, 1.4.21-1, 1.4.20-1

Timeline

References

Open in Interactive Console →