Executive brief
Netty is a widely used networking framework for Java applications. A vulnerability in its handling of WebSocket connections allows an attacker to trick the system into switching communication protocols without a security proxy noticing. This can lead to 'request smuggling,' where an attacker can bypass security filters to access internal data or interfere with other users' web traffic.
Technical details
A vulnerability exists in Netty's `netty-codec-http` component due to insufficient validation in the WebSocket V07 and V08 handshakers. An attacker can initiate a protocol switch by sending a `Sec-WebSocket-Version: 7` header while omitting the mandatory `Connection: Upgrade` and `Upgrade: websocket` headers. Because these standard upgrade headers are missing, intermediary proxies may fail to recognize the protocol switch, while the Netty backend completes it. This inconsistency enables HTTP request smuggling and protocol-confusion attacks. The issue is resolved in versions 4.1.136.Final and 4.2.16.Final.
Affected products
- Netty netty-codec-http < 4.1.136.Final, >= 4.2.0.Final, < 4.2.16.Final
Timeline
- 2026-07-07: patched: Version 4.2.16.Final released
- 2026-07-08: patched: Version 4.1.136.Final released
- 2026-07-14: advisory: GitHub Security Advisory GHSA-4mp9-239f-g9hg published
- 2026-07-29: disclosed: CVE-2026-59898 published to NVD