PT-2019-5206 · Apache+1 · Netty+1

Miguel Costa

·

Published

2019-09-26

·

Updated

2025-07-07

·

CVE-2019-16869

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Netty versions prior to 4.1.42.Final
Description The issue is related to the incorrect handling of whitespace before the colon in HTTP headers, such as a "Transfer-Encoding : chunked" line. This can lead to HTTP request smuggling, allowing a remote attacker to impact data integrity.
Recommendations For versions prior to 4.1.42.Final, update to version 4.1.42.Final or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable HTTP header handling functionality until a patch is available. Avoid using whitespace before the colon in HTTP headers, such as Transfer-Encoding : chunked, in the affected API endpoints until the issue is resolved.

Exploit

Fix

HTTP Request/Response Smuggling

Weakness Enumeration

Related Identifiers

BDU:2020-01935
CVE-2019-16869
DLA-1941-1
DLA-2110-1
DLA-2364-1
DLA-2365-1
DSA-4597-1
GHSA-P979-4MFW-53VG
OESA-2024-2066
OESA-2024-2067
OESA-2024-2068
OESA-2024-2069
OESA-2024-2103
RHSA-2020:0159
RHSA-2020:0160
RHSA-2020:0161
RHSA-2024:5856
USN-4532-1
USN-4600-1

Affected Products

Netty
Ubuntu