PT-2024-7028 · Unknown+2 · Resteasy-Netty4+2

Txema-Martinez-Scopely

·

Published

2024-10-07

·

Updated

2025-07-10

·

CVE-2024-9622

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions resteasy-netty4 library (affected versions not specified)
Description A vulnerability was found in the resteasy-netty4 library arising from improper handling of HTTP requests using smuggling techniques. When an HTTP smuggling request with an ASCII control character is sent, it causes the Netty HttpObjectDecoder to transition into a BAD MESSAGE state. As a result, any subsequent legitimate requests on the same connection are ignored, leading to client timeouts. This issue may impact systems using load balancers and expose them to risk. The vulnerability can be exploited by a remote attacker to send hidden HTTP requests, also known as HTTP Request Smuggling attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

HTTP Request/Response Smuggling

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-08282
CVE-2024-9622
GHSA-5WPR-CJ9P-959R
USN-7351-1
USN-7630-1

Affected Products

Linuxmint
Ubuntu
Resteasy-Netty4