Request Smuggling Vulnerability in Netty by The Netty Project
CVE-2026-89044
What is CVE-2026-89044?
The affected versions of Netty inadvertently mishandle the validation of the final transfer coding specified in the Transfer-Encoding header. This flaw enables attackers to exploit malformed encoding declarations to execute request smuggling attacks. By manipulating Transfer-Encoding headers, such as splitting them across multiple lines or using unconventional values like 'chunked, xchunked', an attacker could persuade the system to incorrectly process requests. As a consequence, malicious actors may gain the ability to send unauthorized requests, complicating the integrity and security of web applications using these Netty versions.
Affected Version(s)
netty 4.1.133.Final < 4.1.138.Final
netty 4.2.13.Final < 4.2.18.Final
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
