Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-93573

Опубликовано: 10 сент. 2026
Источник: redhat
CVSS3: 6.5

Описание

A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allows a remote attacker to bypass Transfer-Encoding header validation by splitting the Transfer-Encoding field across multiple headers, with the last field containing a non-final transfer coding like gzip or deflate. This bypass can lead to HTTP request smuggling, enabling attackers to bypass security controls, desynchronize request processing, or cause requests to be processed in an unintended context.

Отчет

This flaw in Netty's HTTP/1.1 decoder allows for HTTP request smuggling by incorrectly processing split Transfer-Encoding headers. When Netty is deployed with an intermediary that interprets these headers differently, an attacker could bypass front-end security controls or desynchronize request processing.

Меры по смягчению последствий

See https://github.com/netty/netty/security/advisories/GHSA-3jrc-fchc-59pw for fixed versions and remediation guidance.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AMQ Broker 7netty-codec-httpFix deferred
Red Hat AMQ Clientsnetty-codec-httpFix deferred
Red Hat build of Apache Camel 4 for Quarkus 3netty-codec-httpFix deferred
Red Hat build of Apache Camel for Spring Boot 4netty-codec-httpFix deferred
Red Hat build of Apicurio Registry 3netty-codec-httpOut of support scope
Red Hat build of Debezium 3netty-codec-httpFix deferred
Red Hat Build of Keycloaknetty-codec-httpOut of support scope
Red Hat build of Quarkusnetty-codec-httpFix deferred
Red Hat Data Grid 8netty-codec-httpOut of support scope
Red Hat Fuse 7netty-codec-httpOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-444
https://bugzilla.redhat.com/show_bug.cgi?id=2536964io.netty/netty-codec-http: Netty split Transfer-Encoding fields bypass final-chunked validation and enable request smuggling

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
3 дня назад

A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allows a remote attacker to bypass `Transfer-Encoding` header validation by splitting the `Transfer-Encoding` field across multiple headers, with the last field containing a non-final transfer coding like `gzip` or `deflate`. This bypass can lead to HTTP request smuggling, enabling attackers to bypass security controls, desynchronize request processing, or cause requests to be processed in an unintended context.

CVSS3: 6.5
debian
3 дня назад

A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allow ...

CVSS3: 6.5
github
3 дня назад

Netty split Transfer-Encoding fields bypass final-chunked validation and enable request smuggling

6.5 Medium

CVSS3