HIGH 7.5 Maven

HTTP Request Smuggling in Netty

GHSA-p979-4mfw-53vg · CVE-2019-16869

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling.

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes