Skip to content

[UNDERTOW-2594][UNDERTOW-2595][UNDERTOW-2596] CVE-2026-28368 CVE-2026-28369 CVE-2026-28367 Switching to strict HTTP parser#1949

Open
fl4via wants to merge 2 commits intoundertow-io:mainfrom
fl4via:UNDERTOW-2594
Open

[UNDERTOW-2594][UNDERTOW-2595][UNDERTOW-2596] CVE-2026-28368 CVE-2026-28369 CVE-2026-28367 Switching to strict HTTP parser#1949
fl4via wants to merge 2 commits intoundertow-io:mainfrom
fl4via:UNDERTOW-2594

Conversation

@fl4via
Copy link
Copy Markdown
Member

@fl4via fl4via commented Apr 22, 2026

ropalka added 2 commits April 22, 2026 10:44
…-28369 CVE-2026-28367 Switching to strict HTTP parser

Signed-off-by: Flavia Rainone <frainone@redhat.com>
…sure the query is decoded if ALLOW_UNESCAPED_CHARACTERS_IN_URL is set to true and any of the path or query params requires decoding
@fl4via fl4via added bug fix Contains bug fix(es) next release This PR will be merged before next release or has already been merged (for payload double check) waiting CI check Ready to be merged but waiting for CI check labels Apr 22, 2026
@fl4via fl4via added failed CI Introduced new regession(s) during CI check and removed waiting CI check Ready to be merged but waiting for CI check labels Apr 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug fix Contains bug fix(es) failed CI Introduced new regession(s) during CI check next release This PR will be merged before next release or has already been merged (for payload double check)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants