Junglewise Threat Intelligence

CVE-2026-56746: Netty security bypass in CorsHandler origin evaluation

CVE-2026-56746 · Severity: medium · CVSS 6.5 · Published 2026-07-21

Technologies: Netty Project Netty codec-http, Netty-Codec-Http. Vendors: Netty Project, Netty.

Executive brief

Netty, a widely used networking framework for Java applications, contains a flaw in its Cross-Origin Resource Sharing (CORS) protection mechanism. This security feature is intended to block unauthorized web requests from reaching a backend application. An attacker can bypass these restrictions, potentially allowing unauthorized web-based interactions with the application that should have been blocked.

Technical details

A logic error exists in io.netty.handler.codec.http.cors.CorsHandler where the short-circuit mechanism, intended to reject unauthorized origins before they reach the backend, can be bypassed. The getForOrigin method incorrectly returns a configuration object when an 'Origin: null' header is received, regardless of whether the developer has explicitly allowed null origins via isNullOriginAllowed(). This causes the short-circuit check to evaluate as false, forwarding the unauthorized request to the backend application. The vulnerability is tracked as CVE-2026-56746 and is resolved in versions 4.1.136.Final and 4.2.16.Final.

Affected products

  • Netty netty-codec-http >= 4.2.0.Final, < 4.2.16.Final; < 4.1.136.Final

Timeline

  • 2026-07-20: disclosed
  • 2026-07-21: advisory: NVD publication date
  • 2026-07-22: patched: GitHub Advisory published/reviewed

References

Related threats