Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 Maven

HTTP Request Smuggling in Netty

GHSA-ff2w-cq2g-wv5f · CVE-2020-7238

Published · Modified

Description

Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line) and a later Content-Length header. This issue exists because of an incomplete fix for CVE-2019-16869.

Ready to move

Start Securing

Free, no credit card | First findings in minutes