Impact
The flaw resides in Netty’s HTTP/1 decoder where Transfer‑Encoding headers are not fully validated. This allows a remote attacker to send crafted HTTP requests that cause the server to parse subsequent data as a separate HTTP request, enabling injection of arbitrary requests and potential bypass of security controls or access to unauthorized resources. The weakness corresponds to CWE‑1035, a malformed input error leading to request smuggling.
Affected Systems
Affected systems include Red Hat AMQ Broker 7; Red Hat AMQ Clients; Red Hat build of Keycloak; Red Hat Data Grid 8; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat Single Sign‑On 7; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; and Red Hat build of Quarkus.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. EPSS is not available and the vulnerability is not listed in CISA KEV, suggesting that exploitation is possible but not yet widely observed. The likely attack vector is remote over an HTTP connection where an attacker can control request headers, especially Transfer‑Encoding, to smuggle requests between downstream peers or proxies. Successful exploitation can enable an attacker to inject or modify traffic, potentially obtaining confidential data or escalating privileges in the affected deployments.
OpenCVE Enrichment