VDB
KO
HIGH 7.5

GHSA-p979-4mfw-53vg

HTTP Request Smuggling in Netty

Details

Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven / io.netty:netty-all
Introduced in: 4.0.0.Beta1 Fixed in: 4.1.42.Final
Fix # pom.xml: bump <version>4.1.42.Final</version> for io.netty:netty-all
Maven / org.jboss.netty:netty
Introduced in: 0

No fixed version published yet for org.jboss.netty:netty (maven). Pin to a known-safe version or switch to an alternative.

Maven / io.netty:netty
Introduced in: 3.3.0.Final

No fixed version published yet for io.netty:netty (maven). Pin to a known-safe version or switch to an alternative.

References