Количество 4
Количество 4
CVE-2026-93573
A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allows a remote attacker to bypass `Transfer-Encoding` header validation by splitting the `Transfer-Encoding` field across multiple headers, with the last field containing a non-final transfer coding like `gzip` or `deflate`. This bypass can lead to HTTP request smuggling, enabling attackers to bypass security controls, desynchronize request processing, or cause requests to be processed in an unintended context.
CVE-2026-93573
A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allows a remote attacker to bypass `Transfer-Encoding` header validation by splitting the `Transfer-Encoding` field across multiple headers, with the last field containing a non-final transfer coding like `gzip` or `deflate`. This bypass can lead to HTTP request smuggling, enabling attackers to bypass security controls, desynchronize request processing, or cause requests to be processed in an unintended context.
CVE-2026-93573
A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allow ...
GHSA-xvf3-842c-j48x
Netty split Transfer-Encoding fields bypass final-chunked validation and enable request smuggling
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-93573 A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allows a remote attacker to bypass `Transfer-Encoding` header validation by splitting the `Transfer-Encoding` field across multiple headers, with the last field containing a non-final transfer coding like `gzip` or `deflate`. This bypass can lead to HTTP request smuggling, enabling attackers to bypass security controls, desynchronize request processing, or cause requests to be processed in an unintended context. | CVSS3: 6.5 | 0% Низкий | 12 дней назад | |
CVE-2026-93573 A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allows a remote attacker to bypass `Transfer-Encoding` header validation by splitting the `Transfer-Encoding` field across multiple headers, with the last field containing a non-final transfer coding like `gzip` or `deflate`. This bypass can lead to HTTP request smuggling, enabling attackers to bypass security controls, desynchronize request processing, or cause requests to be processed in an unintended context. | CVSS3: 6.5 | 0% Низкий | 3 дня назад | |
CVE-2026-93573 A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allow ... | CVSS3: 6.5 | 0% Низкий | 3 дня назад | |
GHSA-xvf3-842c-j48x Netty split Transfer-Encoding fields bypass final-chunked validation and enable request smuggling | CVSS3: 6.5 | 0% Низкий | 3 дня назад |
Уязвимостей на страницу