Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 Maven

HTTP Request Smuggling in Netty

GHSA-p979-4mfw-53vg · CVE-2019-16869

Published · Modified

Description

Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling.

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes