References https://access.redhat.com/security/cve/cve-2026-3260 https://access.redhat.com/security/cve/cve-2026-28368 https://access.redhat.com/security/cve/cve-2026-28367 https://nvd.nist.gov/vuln/detail/cve-2026-28367 https://nvd.nist.gov/vuln/detail/cve-2025-12543 https://access.redhat.com/security/cve/cve-2025-12543 https://app.opencve.io/cve/?page=2&product=undertow&vendor=redhat https://www.cvedetails.com/version/1395105/Redhat-Undertow-2.2.16.html https://stack.watch/product/redhat/undertow/ https://www.sentinelone.com/vulnerability-database/cve-2020-10705/ https://www.endorlabs.com/learn/cve-2025-12543-host-header-validation-bypass-in-undertow https://cybersecuritynews.com/undertow-http-server-vulnerability/
Related Vulnerabilities(CVE-2024-3653) Undertow learning-push 配置不当漏洞Jboss EAP undertow AJP connector 路径遍历漏洞