VDB
Sign up
MEDIUM5.9

GHSA-f256-j965-7f32

Possible request smuggling in HTTP/2 due missing validation of content-length

Quick fix

GHSA-f256-j965-7f32 — io.netty:netty-codec-http2: upgrade to the fixed version with the command below.

# pom.xml: bump <version>4.1.61.Final</version> for io.netty:netty-codec-http2

Details

### Impact The content-length header is not correctly validated if the request only use a single Http2HeaderFrame with the endStream set to to true. This could lead to request smuggling if the request is proxied to a remote peer and translated to HTTP/1.1

This is a followup of https://github.com/netty/netty/security/advisories/GHSA-wm47-8v5p-wjpj which did miss to fix this one case.

### Patches This was fixed as part of 4.1.61.Final

### Workarounds Validation can be done by the user before proxy the request by validating the header.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/io.netty:netty-codec-http2
Introduced in: 4.0.0Fixed in: 4.1.61.Final
Fix# pom.xml: bump <version>4.1.61.Final</version> for io.netty:netty-codec-http2
Maven/org.jboss.netty:netty
Introduced in: 0

No fixed version published yet for org.jboss.netty:netty (maven). Pin to a known-safe version or switch to an alternative.

Maven/io.netty:netty
Introduced in: 0

No fixed version published yet for io.netty:netty (maven). Pin to a known-safe version or switch to an alternative.

References