Junglewise Threat Intelligence

CVE-2026-59898: Netty HTTP request smuggling via lax WebSocket handshake validation

CVE-2026-59898 · Severity: medium · CVSS 4 · Published 2026-07-29

Technologies: Netty-Codec-Http. Vendors: Netty.

Executive brief

Netty is a widely used networking framework for Java applications. A vulnerability in its handling of WebSocket connections allows an attacker to trick the system into switching communication protocols without a security proxy noticing. This can lead to 'request smuggling,' where an attacker can bypass security filters to access internal data or interfere with other users' web traffic.

Technical details

A vulnerability exists in Netty's `netty-codec-http` component due to insufficient validation in the WebSocket V07 and V08 handshakers. An attacker can initiate a protocol switch by sending a `Sec-WebSocket-Version: 7` header while omitting the mandatory `Connection: Upgrade` and `Upgrade: websocket` headers. Because these standard upgrade headers are missing, intermediary proxies may fail to recognize the protocol switch, while the Netty backend completes it. This inconsistency enables HTTP request smuggling and protocol-confusion attacks. The issue is resolved in versions 4.1.136.Final and 4.2.16.Final.

Affected products

  • Netty netty-codec-http < 4.1.136.Final, >= 4.2.0.Final, < 4.2.16.Final

Timeline

  • 2026-07-07: patched: Version 4.2.16.Final released
  • 2026-07-08: patched: Version 4.1.136.Final released
  • 2026-07-14: advisory: GitHub Security Advisory GHSA-4mp9-239f-g9hg published
  • 2026-07-29: disclosed: CVE-2026-59898 published to NVD

References