Executive brief
Netty, a widely used networking framework for Java applications, contains a flaw in its Cross-Origin Resource Sharing (CORS) protection mechanism. This security feature is intended to block unauthorized web requests from reaching a backend application. An attacker can bypass these restrictions, potentially allowing unauthorized web-based interactions with the application that should have been blocked.
Technical details
A logic error exists in io.netty.handler.codec.http.cors.CorsHandler where the short-circuit mechanism, intended to reject unauthorized origins before they reach the backend, can be bypassed. The getForOrigin method incorrectly returns a configuration object when an 'Origin: null' header is received, regardless of whether the developer has explicitly allowed null origins via isNullOriginAllowed(). This causes the short-circuit check to evaluate as false, forwarding the unauthorized request to the backend application. The vulnerability is tracked as CVE-2026-56746 and is resolved in versions 4.1.136.Final and 4.2.16.Final.
Affected products
- Netty netty-codec-http >= 4.2.0.Final, < 4.2.16.Final; < 4.1.136.Final
Timeline
- 2026-07-20: disclosed
- 2026-07-21: advisory: NVD publication date
- 2026-07-22: patched: GitHub Advisory published/reviewed