Skip to content

[GHSA-j382-5jj3-vw4j] Undertow HTTP server core doesn't properly validate the Host header in incoming HTTP requests#6795

Merged
advisory-database[bot] merged 1 commit intodpogorelov/advisory-improvement-6795from
dpogorelov-GHSA-j382-5jj3-vw4j
Feb 6, 2026
Merged

[GHSA-j382-5jj3-vw4j] Undertow HTTP server core doesn't properly validate the Host header in incoming HTTP requests#6795
advisory-database[bot] merged 1 commit intodpogorelov/advisory-improvement-6795from
dpogorelov-GHSA-j382-5jj3-vw4j

Conversation

@dpogorelov
Copy link

@github-actions github-actions bot changed the base branch from main to dpogorelov/advisory-improvement-6795 February 6, 2026 12:31
@dpogorelov
Copy link
Author

Evidence

From the commit history https://github.com/undertow-io/undertow/commits/2.2.x/?before=38e954a599c77f6248ecdd63df45262c67f24be9+35, the fix commits are:

  • bdc86d1 (Nov 4, 2025): "Add handler to scrutinize Host header in request"
  • 5db5baa (Dec 4, 2025): "Add checks for empty Host header"

Both were merged to the 2.2.x branch before the 2.2.39.Final release on Feb 5, 2026.

@advisory-database advisory-database bot merged commit a0bca21 into dpogorelov/advisory-improvement-6795 Feb 6, 2026
4 checks passed
@advisory-database
Copy link
Contributor

Hi @dpogorelov! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

@advisory-database advisory-database bot deleted the dpogorelov-GHSA-j382-5jj3-vw4j branch February 6, 2026 15:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant