GHSA-p979-4mfw-53vgHighCVSS 7.5

HTTP Request Smuggling in Netty

Published
October 11, 2019
Last Modified
June 29, 2026

🔗 CVE IDs covered (1)

📋 Description

Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling.

🎯 Affected products3

  • maven/io.netty:netty-all:>= 4.0.0.Beta1, < 4.1.42.Final
  • maven/org.jboss.netty:netty:<= 3.2.9.Final
  • maven/io.netty:netty:>= 3.3.0.Final, <= 4.0.0.Alpha8

🔗 References (82)