WebSocket Vulnerability in Netty Framework by Netty
CVE-2026-59898

6.3MEDIUM

Key Information:

Vendor

Netty

Status
Vendor
CVE Published:
29 July 2026

What is CVE-2026-59898?

An identified vulnerability in the Netty framework allows attackers to exploit WebSocket upgrade requests through an improper handshaker. By utilizing a specific version of the Sec-WebSocket-Version header and omitting critical headers like Connection and Upgrade, attackers can manipulate the protocol to conduct HTTP request smuggling and protocol confusion attacks. This issue has been resolved in Netty versions 4.1.136.Final and 4.2.16.Final, enhancing the framework's security against such exploitation.

Affected Version(s)

netty >=4.2.0.Final, < 4.2.16.Final < 4.2.0.Final, 4.2.16.Final

netty < 4.1.136.Final < 4.1.136.Final

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.