HIGH 7.5 Maven

HTTP Request Smuggling in Netty

GHSA-ff2w-cq2g-wv5f · CVE-2020-7238

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line) and a later Content-Length header. This issue exists because of an incomplete fix for CVE-2019-16869.

Ready to move

Start Securing

Free, no credit card | First findings in minutes