Junglewise Threat Intelligence

CVE-2026-33870: Netty request smuggling via chunked extension quoted-string parsing

CVE-2026-33870 · Severity: high · CVSS 7.5 · Published 2026-03-27

Technologies: Red Hat AMQ Broker, Netty-Codec-Http. Vendors: Red Hat, Netty.

Executive brief

Netty is a popular networking framework used by many Java-based applications and servers to handle web traffic. A flaw in how it processes specific types of web requests (chunked transfer encoding) allows an attacker to 'smuggle' a hidden second request inside a legitimate-looking one. This can be used to bypass security filters, poison web caches, or gain unauthorized access to sensitive data by tricking the server into misinterpreting the boundaries between different user requests.

Technical details

A request smuggling vulnerability exists in Netty's HTTP codec due to improper handling of quoted strings in chunk extensions. According to RFC 9110, chunk extensions can contain quoted strings that may include various characters; however, Netty's parser incorrectly terminates the chunk header when it encounters a CR/LF sequence even if it is inside a quoted string. An attacker can exploit this parsing differential by crafting a chunked request where a smuggled HTTP request is hidden within a quoted-string extension value. While the RFC technically forbids CR/LF within these strings, Netty's failure to reject the malformed request or parse it consistently with downstream proxies allows for the injection of arbitrary requests. This issue is fixed in versions 4.1.132.Final and 4.2.10.Final.

Affected products

  • Netty netty-codec-http < 4.1.132.Final, < 4.2.10.Final
  • Red Hat Red Hat JBoss Enterprise Application Platform 8.1
  • Red Hat Red Hat AMQ Broker 7.12.7
  • Red Hat Red Hat Data Grid 8.6.1

Timeline

  • 2026-03-24: advisory: GitHub Security Advisory GHSA-pwqr-wmgm-9rr8 published
  • 2026-03-27: disclosed: CVE-2026-33870 published to NVD

References

Related threats