Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
DLA-1941-1 | netty security update |
![]() |
DLA-2110-1 | netty-3.9 security update |
![]() |
DLA-2364-1 | netty security update |
![]() |
DLA-2365-1 | netty-3.9 security update |
![]() |
DSA-4597-1 | netty security update |
![]() |
EUVD-2019-0710 | Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling. |
![]() |
GHSA-p979-4mfw-53vg | HTTP Request Smuggling in Netty |
![]() |
USN-4532-1 | Netty vulnerabilities |
![]() |
USN-4600-1 | Netty vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 07 Jul 2025 17:15:00 +0000
Mon, 26 Aug 2024 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Redhat jboss Enterprise Application Platform Eus
|
|
CPEs | cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7 | |
Vendors & Products |
Redhat jboss Enterprise Application Platform Eus
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-07-07T16:57:29.928Z
Reserved: 2019-09-25T00:00:00.000Z
Link: CVE-2019-16869

No data.

Status : Modified
Published: 2019-09-26T16:15:11.690
Modified: 2025-07-07T17:15:26.303
Link: CVE-2019-16869


No data.