Executive brief
Netty is a widely used networking framework that helps applications communicate over the internet. A flaw in how it handles certain web requests allows an attacker to 'smuggle' hidden commands past security filters by confusing the system about where one request ends and the next begins. This could allow an attacker to bypass security controls, access restricted internal data, or interfere with other users' web sessions.
Technical details
A request smuggling vulnerability exists in Netty's HttpObjectDecoder due to inconsistent handling of HTTP/1.0 vs HTTP/1.1 protocol versions. While Netty correctly strips the Content-Length header when Transfer-Encoding: chunked is present in HTTP/1.1, it fails to do so for HTTP/1.0 requests. An attacker can send a specially crafted HTTP/1.0 request with both headers, causing Netty to process the body as chunked while forwarding the original Content-Length to downstream components. If a downstream proxy prioritizes Content-Length, it will misinterpret the message boundaries, allowing the attacker to inject a second, 'smuggled' request. This is fixed in versions 4.2.13.Final and 4.1.133.Final.
Affected products
- Netty netty-codec-http <= 4.2.12.Final, <= 4.1.132.Final
Timeline
- 2026-05-05: advisory: GitHub advisory GHSA-xxqh-mfjm-7mv9 published
- 2026-05-13: disclosed: CVE-2026-42581 published to NVD