CVE-2017-12165

LOW

Undertow <1.4.17, <1.3.31, <2.0.0 - HTTP Request Smuggling

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2017-12165. PoCs published by dawetmaster, andikahilmy.

AI-analyzed exploit summary The repository contains only the source code of Undertow, a Java web server, without any exploit code or technical analysis related to CVE-2017-12165. The README provides no details about the vulnerability or how to exploit it.

Description

It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces which can cause possible http request smuggling.

Exploits (2)

nomisec STUB
by dawetmaster · poc
https://github.com/dawetmaster/CVE-2017-12165-undertow-vulnerable

The repository contains only the source code of Undertow, a Java web server, without any exploit code or technical analysis related to CVE-2017-12165. The README provides no details about the vulnerability or how to exploit it.

Classification
Stub 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: Undertow (version not specified)
No auth needed
Prerequisites: none
devstral-2 · analyzed Mar 14, 2026 Full analysis →
nomisec STUB
by andikahilmy · poc
https://github.com/andikahilmy/CVE-2017-12165-undertow-vulnerable

The repository contains a partial snapshot of the Undertow web server source code but lacks any exploit code or technical analysis related to CVE-2017-12165. The README is a generic description of Undertow without vulnerability details.

Classification
Stub 90%
Attack Type
Other
Complexity
Theoretical
Reliability
Theoretical
Target: Undertow (version unspecified)
No auth needed
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (10)

Core 10
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:1322
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:0002
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:3458
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:0004
Issue Tracking, Vendor Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-12165
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:3455
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:3456
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:0003
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:0005
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:3454

Scores

CVSS v3 2.6
EPSS 0.0110
EPSS Percentile 78.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N

Details

CWE
CWE-444
Status published
Products (5)
io.undertow/undertow-core 0 - 1.3.31Maven
redhat/jboss_enterprise_application_platform 7.0.0
redhat/jboss_enterprise_application_platform 7.1.0
redhat/undertow 2.0.0 alpha_1
redhat/undertow 1.0.0 - 1.3.31
Published Jul 27, 2018
Tracked Since Feb 18, 2026