CVE-2019-16869 — HTTP Request Smuggling in Netty
Severity
7.5HIGHNVD
EPSS
4.0%
top 11.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 26
Latest updateOct 27
Description
Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6
Affected Packages3 packages
Also affects: Debian Linux 10.0, 8.0, 9.0, Ubuntu Linux 18.04
Patches
🔴Vulnerability Details
8📋Vendor Advisories
5Red Hat
▶
Debian▶
CVE-2019-16869: netty - Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers...↗2019