Request Smuggling Vulnerability in Netty by The Netty Project
CVE-2026-89044

6.9MEDIUM

Key Information:

Vendor

Netty

Status
Vendor
CVE Published:
10 September 2026

What is CVE-2026-89044?

The affected versions of Netty inadvertently mishandle the validation of the final transfer coding specified in the Transfer-Encoding header. This flaw enables attackers to exploit malformed encoding declarations to execute request smuggling attacks. By manipulating Transfer-Encoding headers, such as splitting them across multiple lines or using unconventional values like 'chunked, xchunked', an attacker could persuade the system to incorrectly process requests. As a consequence, malicious actors may gain the ability to send unauthorized requests, complicating the integrity and security of web applications using these Netty versions.

Affected Version(s)

netty 4.1.133.Final < 4.1.138.Final

netty 4.2.13.Final < 4.2.18.Final

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yu Bao, PayPal Cyber Security Team
dreamlike-ocean
Michael-JRead
.