CVE-2020-7238

HIGH7.5EPSS 1.5%

HTTP Request Smuggling in Netty

Published: 2/21/2020Modified: 3/14/2024
Also known as:GHSA-ff2w-cq2g-wv5f

Description

Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line) and a later Content-Length header. This issue exists because of an incomplete fix for CVE-2019-16869.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

References (22)