CVE-2026-33870

HIGH

Netty: HTTP Request Smuggling via Chunked Extension Quoted-String Parsing

Title source: cna
STIX 2.1

Description

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.

Scores

CVSS v3 7.5
EPSS 0.0001
EPSS Percentile 3.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-444
Status published
Products (4)
io.netty/netty-codec-http 0 - 4.1.132.FinalMaven
netty/netty < 4.1.132
netty/netty < 4.1.132.Final
netty/netty >= 4.2.0.Alpha1, < 4.2.10.Final
Published Mar 27, 2026
Tracked Since Mar 29, 2026