Description
A flaw was found in Netty. A remote attacker could exploit this by sending a specially crafted HTTP request that includes control characters within the chunk-size line. This bypasses the intended strict validation, allowing the attacker to inject arbitrary HTTP requests. This vulnerability can lead to HTTP request smuggling, potentially resulting in information disclosure or other unauthorized actions.
Published: 2026-09-18
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: HTTP request smuggling
Action: Apply Patch
AI Analysis

Impact

Netty skips strict validation of chunk size lines when no chunk extension is present, allowing lines such as "0\rX" to be accepted instead of rejected. This deviation from RFC 9112 enables HTTP request smuggling, letting an attacker send crafted requests that are parsed in a split or reversed manner by the server. The resulting smuggling can allow the attacker to insert or manipulate subsequent requests, potentially bypassing authentication, firewall rules, or content filters, and may also lead to denial‑of‑service conditions when malformed chunks are processed repeatedly.

Affected Systems

The flaw affects numerous Red Hat distributions that include Netty in their application stacks, including Red Hat AMQ Broker 7, Red Hat AMQ Clients, Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7 and 8, Red Hat Single Sign‑On 7, Red Hat Build of Apache Camel 4 for Quarkus 3, Red Hat Build of Apache Camel for Spring Boot 4, Red Hat Build of Apicurio Registry 3, Red Hat Build of Debezium 3, and Red Hat Build of Quarkus. Specific version information is not provided in this advisory, so any deployment using an affected Netty library requires review.

Risk and Exploitability

The CVSS score of 6.5 classifies this vulnerability as medium. The EPSS score indicates a very low exploitation probability (<1%) and it is not listed in the CISA KEV catalog, implying that active exploitation has not been observed or recorded. The likely attack vector is remote: an adversary can deliver the malformed request over the network to any exposed HTTP interface that uses Netty for request decoding. The lack of proper chunk‑size validation enables request smuggling, which can lead to covert data exfiltration, privilege escalation, or service disruption, depending on how the target application handles subsequent requests.

Generated by OpenCVE AI on September 19, 2026 at 16:24 UTC.

Remediation

Vendor Workaround

See https://github.com/netty/netty/security/advisories/GHSA-rq4j-fc47-9698 for fixed versions and remediation guidance.


OpenCVE Recommended Actions

  • Update the Netty library to a corrected version as specified in the GitHub advisory (GHSA‑rq4j‑fc47‑9698) or apply the vendor‑issued security patch for the affected Red Hat distribution. This resolves the faulty chunk‑size parsing logic.
  • If an immediate upgrade is not feasible, configure any reverse proxies, API gateways, or network load balancers in front of the affected services to enforce strict RFC 9112 chunk‑size validation and reject any request with non‑hexadecimal or control‑character bytes in the chunk‑size line. This mitigates the smuggling vector until a patch can be applied.
  • Review application logs for anomalous HTTP requests that contain non‑standard chunk‑size lines and investigate any corresponding downstream request handling anomalies. Immediate operational monitoring can help detect active exploitation attempts.

Generated by OpenCVE AI on September 19, 2026 at 16:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
References

Mon, 21 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Red Hat
Red Hat red Hat Amq Broker 7
Redhat build Of Apache Camel For Quarkus
Redhat build Of Apache Camel For Spring Boot
Redhat build Of Apicurio Registry
Redhat build Of Debezium 3
Redhat build Of Keycloak
Redhat build Of Quarkus
Redhat data Grid 8
Redhat quay 3
Redhat single Sign-on
Vendors & Products Red Hat
Red Hat red Hat Amq Broker 7
Redhat build Of Apache Camel For Quarkus
Redhat build Of Apache Camel For Spring Boot
Redhat build Of Apicurio Registry
Redhat build Of Debezium 3
Redhat build Of Keycloak
Redhat build Of Quarkus
Redhat data Grid 8
Redhat quay 3
Redhat single Sign-on

Mon, 21 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:quarkus:3
Vendors & Products Redhat quarkus
References

Sat, 19 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description ### Summary Netty skips strict chunk size line validation when the line has no chunk extension (`;`), so a chunk size line containing an embedded bare CR (e.g. `0\rX`) is accepted instead of rejected, enabling HTTP request smuggling. ### Details `io.netty.handler.codec.http.HttpObjectDecoder#checkChunkExtensions` only runs the strict validator `HttpChunkLineValidatingByteProcessor` when a `;` is present: ```java int extensionsStart = line.bytesBefore((byte) ';'); if (extensionsStart == -1) { return; } ``` According to RFC 9112 https://datatracker.ietf.org/doc/html/rfc9112#appendix-A `chunk-size = 1*HEXDIG` ### PoC ```java @Test public void test() { String requestStr = "POST / HTTP/1.1\r\n" + "Host: localhost\r\n" + "Transfer-Encoding: chunked\r\n\r\n" + "0\rX\r\n" + "\r\n" + "GET /smuggled HTTP/1.1\r\n" + "Host: localhost\r\n" + "Content-Length: 0\r\n" + "\r\n"; EmbeddedChannel channel = new EmbeddedChannel(new HttpRequestDecoder()); assertTrue(channel.writeInbound(Unpooled.copiedBuffer(requestStr, Ch A flaw was found in Netty. A remote attacker could exploit this by sending a specially crafted HTTP request that includes control characters within the chunk-size line. This bypasses the intended strict validation, allowing the attacker to inject arbitrary HTTP requests. This vulnerability can lead to HTTP request smuggling, potentially resulting in information disclosure or other unauthorized actions.

Fri, 18 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description ### Summary Netty skips strict chunk size line validation when the line has no chunk extension (`;`), so a chunk size line containing an embedded bare CR (e.g. `0\rX`) is accepted instead of rejected, enabling HTTP request smuggling. ### Details `io.netty.handler.codec.http.HttpObjectDecoder#checkChunkExtensions` only runs the strict validator `HttpChunkLineValidatingByteProcessor` when a `;` is present: ```java int extensionsStart = line.bytesBefore((byte) ';'); if (extensionsStart == -1) { return; } ``` According to RFC 9112 https://datatracker.ietf.org/doc/html/rfc9112#appendix-A `chunk-size = 1*HEXDIG` ### PoC ```java @Test public void test() { String requestStr = "POST / HTTP/1.1\r\n" + "Host: localhost\r\n" + "Transfer-Encoding: chunked\r\n\r\n" + "0\rX\r\n" + "\r\n" + "GET /smuggled HTTP/1.1\r\n" + "Host: localhost\r\n" + "Content-Length: 0\r\n" + "\r\n"; EmbeddedChannel channel = new EmbeddedChannel(new HttpRequestDecoder()); assertTrue(channel.writeInbound(Unpooled.copiedBuffer(requestStr, Ch
Title Io.netty/netty-codec-http: netty: http request smuggling due to control characters in the chunk-size line
First Time appeared Redhat
Redhat amq Broker
Redhat amq Clients
Redhat apicurio Registry
Redhat build Keycloak
Redhat camel Quarkus
Redhat camel Spring Boot
Redhat debezium
Redhat jboss Data Grid
Redhat jboss Enterprise Application Platform
Redhat jboss Fuse
Redhat quarkus
Redhat red Hat Single Sign On
Weaknesses CWE-1035
CPEs cpe:/a:redhat:amq_broker:7
cpe:/a:redhat:amq_clients:2023
cpe:/a:redhat:apicurio_registry:3
cpe:/a:redhat:build_keycloak:
cpe:/a:redhat:camel_quarkus:3
cpe:/a:redhat:camel_spring_boot:4
cpe:/a:redhat:debezium:3
cpe:/a:redhat:jboss_data_grid:8
cpe:/a:redhat:jboss_enterprise_application_platform:7
cpe:/a:redhat:jboss_enterprise_application_platform:8
cpe:/a:redhat:jboss_fuse:7
cpe:/a:redhat:quarkus:3
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat
Redhat amq Broker
Redhat amq Clients
Redhat apicurio Registry
Redhat build Keycloak
Redhat camel Quarkus
Redhat camel Spring Boot
Redhat debezium
Redhat jboss Data Grid
Redhat jboss Enterprise Application Platform
Redhat jboss Fuse
Redhat quarkus
Redhat red Hat Single Sign On
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Red Hat Red Hat Amq Broker 7
Redhat Amq Broker Amq Clients Apicurio Registry Build Keycloak Build Of Apache Camel For Quarkus Build Of Apache Camel For Spring Boot Build Of Apicurio Registry Build Of Debezium 3 Build Of Keycloak Build Of Quarkus Camel Quarkus Camel Spring Boot Data Grid 8 Debezium Jboss Data Grid Jboss Enterprise Application Platform Jboss Fuse Quay 3 Red Hat Single Sign On Single Sign-on
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-24T10:35:41.300Z

Reserved: 2026-09-18T10:00:52.431Z

Link: CVE-2026-93566

cve-icon Vulnrichment

Updated: 2026-09-22T14:28:35.539Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T15:17:20.290

Modified: 2026-09-24T11:16:59.840

Link: CVE-2026-93566

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-10T00:47:37Z

Links: CVE-2026-93566 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:25:31Z

Weaknesses