-
Bug
-
Resolution: Unresolved
-
Major
-
None
-
None
-
None
Undertow splits header names from values on either space or colon, whichever comes first. This allows for the construction of crafted requests with headers that are visible only to Undertow, but not upstream proxies, which can be used to launch request smuggling attacks.
(I reported this to the security list in March, but the issue was closed without a substantive response.)