{"id":"CVE-2020-10687","aliases":["GHSA-p9w3-gwc2-cr49"],"url":"https://o3.security/vulnerability/CVE-2020-10687","summary":"HTTP Request Smuggling in Undertow","details":"A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, where HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own.","published":"2020-09-23T13:15:15.157Z","modified":"2026-07-08T05:55:39.683264803Z","cvss":{"score":4.8,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Maven","name":"io.undertow:undertow-core","fixedVersion":"2.2.0.Final"}],"fix":null,"references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/r6603513ea8afbf6857fd77ca5888ec8385d0af493baa4250e28c351c%40%3Cdev.cxf.apache.org%3E"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20220210-0015/"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1785049"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:55:39.683264803Z"}}