Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Undertow would allow unintended access to user sessions over the network.. ========================================================================== Ubuntu Security Notice USN-8144-1 April 02, 2026 undertow vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Undertow would allow unintended access to user sessions over the network. Software Description: - undertow: Java web server based on non-blocking IO Details: It was discovered that Undertow incorrectly validated the Host header in incoming HTTP requests. A remote attacker could possibly use this issue to gain unintended access to user sessions. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS libundertow-java 2.3.8-2ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS libundertow-java 2.2.16-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS libundertow-java 2.0.29-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS libundertow-java 1.4.23-3ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS libundertow-java 1.3.16-1ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8144-1 CVE-2025-12543 . Undertow in Ubuntu allows unintended session access over the network, requiring immediate updates to mitigate risk.. Undertow Security, Ubuntu Security Notice, Remote Access Issue, User Session Vulnerability. . Severity: Important. LinuxSecurity.com Team
A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling (CVE-2020-10719). References: . MGASA-2021-0052 - Updated undertow packages fix security vulnerability Publication date: 22 Jan 2021 URL: https://advisories.mageia.org/MGASA-2021-0052.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-10719 A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling (CVE-2020-10719). References: - https://bugs.mageia.org/show_bug.cgi?id=28076 - https://security-tracker.debian.org/tracker/CVE-2020-10719 - https://www.cve.org/CVERecord?id=CVE-2020-10719 SRPMS: - 7/core/undertow-1.4.0-2.1.mga7 . Improvements for Undertow rectify a vulnerability allowing HTTP request smuggling exploits in Mageia 7 environments. Security measures detailed.. Mageia Update, Undertow Security, HTTP Request Fix. . Severity: Low. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.