cbcvebase.
CVE-2026-42578
published 2026-05-13

CVE-2026-42578: Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT…

low2.9CVSS 4.0
AVNACLATPPRNUINVCNVILVANSCNSINSANEPCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
candlepinprojectcandlepin
devspacesmulticluster-redirector-rhel9
devspacesopenvsx-rhel9
devspacespluginregistry-rhel9
devspacesserver-rhel9
nettynetty< 4.1.133.Final4.1.133.Final
nettynetty< 4.1.1334.1.133
nettynetty
nettynetty>= 4.2.0 < 4.2.134.2.13
openshift-serverless-1kn-ekb-dispatcher-rhel9
openshift-serverless-1kn-ekb-receiver-rhel9
openshift-serverless-1kn-eventing-integrations-aws-ddb-streams-source-rhel9
openshift-serverless-1kn-eventing-integrations-aws-s3-sink-rhel9
openshift-serverless-1kn-eventing-integrations-aws-s3-source-rhel9
openshift-serverless-1kn-eventing-integrations-aws-sns-sink-rhel9
openshift-serverless-1kn-eventing-integrations-aws-sqs-sink-rhel9
openshift-serverless-1kn-eventing-integrations-aws-sqs-source-rhel9
openshift-serverless-1kn-eventing-integrations-log-sink-rhel9
openshift-serverless-1kn-eventing-integrations-timer-source-rhel9
rhbk-openshift-rhel9rhbk-openshift-rhel9
rhbk-rhel9-operatorrhbk-rhel9-operator
rhbkkeycloak-rhel9
rhbkkeycloak-rhel9-operator
rhoaiodh-modelmesh-rhel8
rhoaiodh-modelmesh-rhel9

CVSS provenance

nvdv4.02.9LOWCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
ghsa6.5MEDIUM