UNKNOWN Maven
Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation
GHSA-4mp9-239f-g9hg · CVE-2026-59898
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Summary
An attacker can force WebSocket upgrade via the lax V07 (or V08) handshaker by sending Sec-WebSocket-Version: 7 and omitting Connection: Upgrade / Upgrade: websocket headers, completing a protocol switch that a proxy would not recognize as an Upgrade request and enabling HTTP request smuggling / protocol-confusion attacks.
Ready to move
Start Securing
Free, no credit card | First findings in minutes