Description
A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to handle chunked transfer encoding. The issue occurs because the parser uses a single internal variable to store both the remaining chunk size and state flags. By sending a specially crafted request with an extremely large chunk size, an attacker can cause these values to overlap, tricking the parser into thinking a request has finished prematurely. This can allow a second, "smuggled" request to be processed out of sync, potentially bypassing security controls.
Published: 2026-08-11
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the ChunkReader component of the Undertow HTTP server, which WildFly and JBoss EAP use to process chunked transfer encoding. Because the parser reuses a single variable for both the remaining chunk size and internal state flags, a client can send a request with an extraordinarily large chunk size that causes the two values to overlap. When this occurs the parser incorrectly believes the current request is finished, allowing a second, smuggled request to be processed out of sync. This flaw is classified as CWE‑444 and can enable an attacker to bypass security controls such as authentication or access‑control checks that rely on the integrity of the request stream.

Affected Systems

Affected systems include Red Hat Enterprise Linux 8, 9, and 10; Red Hat JBoss Enterprise Application Platform versions 7 and 8, including the Expansion Pack; Red Hat Data Grid 8; Red Hat Fuse 7; Red Hat Single Sign‑On 7; and the Red Hat builds of Apache Camel with HawtIO 4 and Spring Boot 4.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. Because the EPSS score is unavailable and the issue is not listed in CISA’s KEV catalog, the likelihood of exploitation by the community remains uncertain, but an attacker with network access to any exposed Undertow‑based service could craft the oversized chunk request to smuggle a second request. The ability to process a second request out of sync could allow unauthorized actions or the bypass of firewall or WAF rules that depend on normal request sequencing.

Generated by OpenCVE AI on August 11, 2026 at 22:51 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Deploy the latest Red Hat security update for the impacted product that includes the fix for CVE‑2026‑14180.
  • If a patch is not yet available, mitigate by blocking or filtering oversized chunk sizes at the network edge or by configuring a reverse proxy to enforce strict chunk‑size limits.
  • Monitor HTTP traffic for abnormal chunk‑size values and anomalous request patterns that may signal an attempt to smuggle a second request.
  • Ensure that all applications using Undertow disable or properly validate chunked transfer encoding if it is not required.

Generated by OpenCVE AI on August 11, 2026 at 22:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat build Of Apache Camel - Hawtio
Redhat build Of Apache Camel For Spring Boot
Redhat data Grid 8
Redhat fuse
Redhat jboss Enterprise Application Platform Expansion Pack
Redhat single Sign On
Vendors & Products Redhat build Of Apache Camel - Hawtio
Redhat build Of Apache Camel For Spring Boot
Redhat data Grid 8
Redhat fuse
Redhat jboss Enterprise Application Platform Expansion Pack
Redhat single Sign On

Wed, 12 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 11 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to handle chunked transfer encoding. The issue occurs because the parser uses a single internal variable to store both the remaining chunk size and state flags. By sending a specially crafted request with an extremely large chunk size, an attacker can cause these values to overlap, tricking the parser into thinking a request has finished prematurely. This can allow a second, "smuggled" request to be processed out of sync, potentially bypassing security controls.
Title Undertow-core: undertow:http request smuggling via oversized chunk-size bit overlap
First Time appeared Redhat
Redhat apache Camel Hawtio
Redhat camel Spring Boot
Redhat enterprise Linux
Redhat jboss Data Grid
Redhat jboss Enterprise Application Platform
Redhat jboss Fuse
Redhat jbosseapxp
Redhat red Hat Single Sign On
Weaknesses CWE-444
CPEs cpe:/a:redhat:apache_camel_hawtio:4
cpe:/a:redhat:camel_spring_boot:4
cpe:/a:redhat:jboss_data_grid:8
cpe:/a:redhat:jboss_enterprise_application_platform:7
cpe:/a:redhat:jboss_enterprise_application_platform:8
cpe:/a:redhat:jboss_fuse:7
cpe:/a:redhat:jbosseapxp
cpe:/a:redhat:red_hat_single_sign_on:7
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat apache Camel Hawtio
Redhat camel Spring Boot
Redhat enterprise Linux
Redhat jboss Data Grid
Redhat jboss Enterprise Application Platform
Redhat jboss Fuse
Redhat jbosseapxp
Redhat red Hat Single Sign On
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Redhat Apache Camel Hawtio Build Of Apache Camel - Hawtio Build Of Apache Camel For Spring Boot Camel Spring Boot Data Grid 8 Enterprise Linux Fuse Jboss Data Grid Jboss Enterprise Application Platform Jboss Enterprise Application Platform Expansion Pack Jboss Fuse Jbosseapxp Red Hat Single Sign On Single Sign On
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-11T18:29:31.703Z

Reserved: 2026-06-30T07:59:30.806Z

Link: CVE-2026-14180

cve-icon Vulnrichment

Updated: 2026-08-11T18:29:26.403Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T16:17:28.923

Modified: 2026-08-14T19:07:46.080

Link: CVE-2026-14180

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-11T11:14:47Z

Links: CVE-2026-14180 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:41:09Z

Weaknesses
  • CWE-444

    Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')