CVE-2019-16869
HTTP Request Smuggling in Netty
Description
Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling.
Base CVSS
7.5
EPSS Score
3.59%
Introduced Version
4.0.0.Alpha1,0,4.0.0.Beta1,4.0.5.Final,4.0.14.Final,5.0.0.Alpha1,4.0.24.Final,5.0.0.Alpha2,3.3.0.Final,3.1.0.ALPHA1
Fix Available
4.1.42.Final
Available Patches
Package
CVEs Fixed
Lines of Code Changed