the Undertow AJP listener honours forged ssl_cert and...
High severity
Unreviewed
Published
Aug 11, 2026
to the GitHub Advisory Database
•
Updated Aug 12, 2026
Description
Published by the National Vulnerability Database
Aug 11, 2026
Published to the GitHub Advisory Database
Aug 11, 2026
Last updated
Aug 12, 2026
the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authentication. This enables an unauthenticated attacker with direct TCP access to port 8009 to bypass CLIENT-CERT authentication by injecting a forged X.509 certificate via the AJP protocol.
References