CVE-2024-9622
published 2024-10-08CVE-2024-9622: A vulnerability was found in the resteasy-netty4 library arising from improper handling of HTTP requests using smuggling techniques. When an HTTP smuggling…
PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.65%
47.0th percentile
A vulnerability was found in the resteasy-netty4 library arising from improper handling of HTTP requests using smuggling techniques. When an HTTP smuggling request with an ASCII control character is sent, it causes the Netty HttpObjectDecoder to transition into a BAD_MESSAGE state. As a result, any subsequent legitimate requests on the same connection are ignored, leading to client timeouts, which may impact systems using load balancers and expose them to risk.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | resteasy | >= 0 < 3.0.6-3ubuntu0.1~esm1 | 3.0.6-3ubuntu0.1~esm1 |
| redhat | resteasy | >= 0 < 3.6.2-2ubuntu0.20.04.1~esm1 | 3.6.2-2ubuntu0.20.04.1~esm1 |
| redhat | resteasy | >= 0 < 3.6.2-2ubuntu0.22.04.1~esm1 | 3.6.2-2ubuntu0.22.04.1~esm1 |
| redhat | resteasy | >= 0 < 3.6.2-2ubuntu0.24.04.1~esm1 | 3.6.2-2ubuntu0.24.04.1~esm1 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
RESTEasy vulnerabilities
vendor_ubuntu·2025-07-10·CVSS 6.5
CVE-2021-20289 [MEDIUM] RESTEasy vulnerabilities
Title: RESTEasy vulnerabilities
Summary: Several security issues were fixed in resteasy, resteasy3.0.
It was discovered that RESTEasy made insufficient use of random values in
asynchronous jobs. An attacker could possibly use this issue to steal
user data. This issue only affected Ubuntu 14.04 LTS. (CVE-2016-6345)
It was discovered that RESTEasy enabled a vulnerable GZIP decompression
module by default. An attacker could possibly use this issue to cause a
denial of service. This issue only affected Ubuntu 14.04 LTS.
(CVE-2016-6346)
It was discovered that RESTEasy improperly made use of unsanitized data
while handling certain errors. An attacker could possibly use this issue
to cause a denial of service or execute arbitrary code.
This issue only affected Ubuntu 14.04 LTS. (CVE-2016-6347
Ubuntu
RESTEasy vulnerabilities
vendor_ubuntu·2025-03-13·CVSS 6.1
CVE-2020-1695 [MEDIUM] RESTEasy vulnerabilities
Title: RESTEasy vulnerabilities
Summary: Several security issues were fixed in RESTEasy.
Nikos Papadopoulos discovered that RESTEasy improperly handled URL encoding
when certain errors occur. An attacker could possibly use this issue to
modify the app's behavior for other users through the network.
(CVE-2020-10688)
Mirko Selber discovered that RESTEasy improperly validated user input
during HTTP response construction. This issue could possibly allow an
attacker to cause a denial of service or execute arbitrary code.
(CVE-2020-1695)
It was discovered that RESTEasy unintentionally disclosed potentially
sensitive server information to users during the handling of certain
errors. (CVE-2020-25633)
It was discovered that RESTEasy unintentionally disclosed parts of its code
to users during t
Red Hat
resteasy-netty4-cdi: resteasy-netty4: resteasy-reactor-netty: HTTP Request Smuggling Leading to Client Timeouts in resteasy-netty4
vendor_redhat·2024-10-08·CVSS 5.3
CVE-2024-9622 [MEDIUM] CWE-444 resteasy-netty4-cdi: resteasy-netty4: resteasy-reactor-netty: HTTP Request Smuggling Leading to Client Timeouts in resteasy-netty4
resteasy-netty4-cdi: resteasy-netty4: resteasy-reactor-netty: HTTP Request Smuggling Leading to Client Timeouts in resteasy-netty4
A vulnerability was found in the resteasy-netty4 library arising from improper handling of HTTP requests using smuggling techniques. When an HTTP smuggling request with an ASCII control character is sent, it causes the Netty HttpObjectDecoder to transition into a BAD_MESSAGE state. As a result, any subsequent legitimate requests on the same connection are ignored, leading to client timeouts, which may impact systems using load balancers and expose them to risk.
A vulnerability was found in the resteasy-netty4 library arising from improper handling of HTTP requests using smuggling techniques. When an HTTP smuggling request with an ASCII control character is se
OSV
resteasy, resteasy3.0 vulnerabilities
osv·2025-07-10·CVSS 6.5
CVE-2016-6345 [MEDIUM] resteasy, resteasy3.0 vulnerabilities
resteasy, resteasy3.0 vulnerabilities
It was discovered that RESTEasy made insufficient use of random values in
asynchronous jobs. An attacker could possibly use this issue to steal
user data. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-6345)
It was discovered that RESTEasy enabled a vulnerable GZIP decompression
module by default. An attacker could possibly use this issue to cause a
denial of service. This issue only affected Ubuntu 16.04 LTS.
(CVE-2016-6346)
It was discovered that RESTEasy improperly made use of unsanitized data
while handling certain errors. An attacker could possibly use this issue
to cause a denial of service or execute arbitrary code.
This issue only affected Ubuntu 16.04 LTS. (CVE-2016-6347)
It was discovered that RESTEasy enabled a vulnerable JSON mani
OSV
resteasy vulnerabilities
osv·2025-03-13·CVSS 6.1
CVE-2020-10688 [MEDIUM] resteasy vulnerabilities
resteasy vulnerabilities
Nikos Papadopoulos discovered that RESTEasy improperly handled URL encoding
when certain errors occur. An attacker could possibly use this issue to
modify the app's behavior for other users through the network.
(CVE-2020-10688)
Mirko Selber discovered that RESTEasy improperly validated user input
during HTTP response construction. This issue could possibly allow an
attacker to cause a denial of service or execute arbitrary code.
(CVE-2020-1695)
It was discovered that RESTEasy unintentionally disclosed potentially
sensitive server information to users during the handling of certain
errors. (CVE-2020-25633)
It was discovered that RESTEasy unintentionally disclosed parts of its code
to users during the handling of certain errors. (CVE-2021-20289)
It was discovere
GHSA
HTTP Request Smuggling Leading to Client Timeouts in resteasy-netty4
ghsa·2024-10-08
CVE-2024-9622 [MEDIUM] CWE-444 HTTP Request Smuggling Leading to Client Timeouts in resteasy-netty4
HTTP Request Smuggling Leading to Client Timeouts in resteasy-netty4
A vulnerability was found in the resteasy-netty4 library arising from improper handling of HTTP requests using smuggling techniques. When an HTTP smuggling request with an ASCII control character is sent, it causes the Netty HttpObjectDecoder to transition into a BAD_MESSAGE state. As a result, any subsequent legitimate requests on the same connection are ignored, leading to client timeouts, which may impact systems using load balancers and expose them to risk.
OSV
HTTP Request Smuggling Leading to Client Timeouts in resteasy-netty4
osv·2024-10-08
CVE-2024-9622 [MEDIUM] HTTP Request Smuggling Leading to Client Timeouts in resteasy-netty4
HTTP Request Smuggling Leading to Client Timeouts in resteasy-netty4
A vulnerability was found in the resteasy-netty4 library arising from improper handling of HTTP requests using smuggling techniques. When an HTTP smuggling request with an ASCII control character is sent, it causes the Netty HttpObjectDecoder to transition into a BAD_MESSAGE state. As a result, any subsequent legitimate requests on the same connection are ignored, leading to client timeouts, which may impact systems using load balancers and expose them to risk.
OSV
CVE-2024-9622: A vulnerability was found in the resteasy-netty4 library arising from improper handling of HTTP requests using smuggling techniques
osv·2024-10-08·CVSS 5.3
CVE-2024-9622 [MEDIUM] CVE-2024-9622: A vulnerability was found in the resteasy-netty4 library arising from improper handling of HTTP requests using smuggling techniques
A vulnerability was found in the resteasy-netty4 library arising from improper handling of HTTP requests using smuggling techniques. When an HTTP smuggling request with an ASCII control character is sent, it causes the Netty HttpObjectDecoder to transition into a BAD_MESSAGE state. As a result, any subsequent legitimate requests on the same connection are ignored, leading to client timeouts, which may impact systems using load balancers and expose them to risk.
No detection rules found.
No public exploits indexed.
2024-10-08
Published