Skip to content
Red HatCVE-2026-19879

Red Hat Undertow: information disclosure

Medium5.3CVE-2026-19879 · Published Aug 14, 2026

A flaw was found in Undertow, an HTTP server, within its HTTP response header writing path. The `writeString()` method performs a silent narrowing cast from 16-bit Unicode characters to 8-bit bytes when writing HTTP response header values. A remote attacker can exploit this by supplying specific Unicode characters in user-controlled input that an application places into response headers. This can lead to the truncation of these characters into ASCII control characters or special symbols, potentially resulting in limited integrity impact or information disclosure if the application does not properly sanitize user input.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Red Hat JBoss Enterprise Application Platform 7
Product
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
Red Hat build of Apache Camel for Spring Boot 4
Product
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-681

More Red Hat advisories

All Red Hat
Advisory
Red Hat Quay: attacker could inject LDAP filter metacharacters
Medium4.8Aug 14
Red Hat Quay: information disclosure
Medium5.3Aug 14
Red Hat Quay.: path traversal
Medium6.5Aug 14
Red Hat Quay: improper signature check
Medium5.9Aug 14
Red Hat Quay: information disclosure
Medium5.9Aug 14
Red Hat Quay: server-side request forgery
Medium4.2Aug 14

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.