CVE-2026-42581
MEDIUMNetty: HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization
Title source: cnaDescription
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
References (11)
Core 11
Core References
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:42644
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:23808
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:24502
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:25123
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:28010
Vendor Advisory
https://access.redhat.com/security/cve/CVE-2026-42581
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2477232
X_Refsource_Confirm x_refsource_confirm
https://github.com/netty/netty/security/advisories/GHSA-xxqh-mfjm-7mv9
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:36820
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:37390
Scores
CVSS v3
5.8
EPSS
0.0061
EPSS Percentile
45.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-444
Status
published
Products (5)
io.netty/netty-codec-http
0 - 4.1.133.FinalMaven
io.netty/netty-codec-http
4.2.0.Alpha1 - 4.2.13.FinalMaven
netty/netty
< 4.1.133
netty/netty
< 4.1.133.Final
netty/netty
>= 4.2.0.Alpha1, < 4.2.13.Final
Published
May 13, 2026
Tracked Since
May 14, 2026