« Back to list

Redhat

Redhat Build OF Apache Camel - Hawtio: vulnerabilities and CVEs

Redhat Build OF Apache Camel - Hawtio has 4 published vulnerabilities, 3 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.

CVEs4
Last 12 months3
Critical3
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-28369Critical (9.1)0.89%—Mar 27, 2026
A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior,…
CVE-2026-28368Critical (9.1)0.89%—Mar 27, 2026
A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in…
CVE-2026-28367Critical (9.1)0.89%—Mar 27, 2026
A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certain proxy servers, such as older versions…
CVE-2024-7885High (7.5)2.6%—Aug 21, 2024
A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue occurs when the parseProxyProtocolV1 method processes multiple…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application3
  2. T1090 Proxy2
  3. T1578 Modify Cloud Compute Infrastructure1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Redhat