Impact
Netty skips strict validation of chunk size lines when no chunk extension is present, allowing lines such as "0\rX" to be accepted instead of rejected. This deviation from RFC 9112 enables HTTP request smuggling, letting an attacker send crafted requests that are parsed in a split or reversed manner by the server. The resulting smuggling can allow the attacker to insert or manipulate subsequent requests, potentially bypassing authentication, firewall rules, or content filters, and may also lead to denial‑of‑service conditions when malformed chunks are processed repeatedly.
Affected Systems
The flaw affects numerous Red Hat distributions that include Netty in their application stacks, including Red Hat AMQ Broker 7, Red Hat AMQ Clients, Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7 and 8, Red Hat Single Sign‑On 7, Red Hat Build of Apache Camel 4 for Quarkus 3, Red Hat Build of Apache Camel for Spring Boot 4, Red Hat Build of Apicurio Registry 3, Red Hat Build of Debezium 3, and Red Hat Build of Quarkus. Specific version information is not provided in this advisory, so any deployment using an affected Netty library requires review.
Risk and Exploitability
The CVSS score of 6.5 classifies this vulnerability as medium. The EPSS score indicates a very low exploitation probability (<1%) and it is not listed in the CISA KEV catalog, implying that active exploitation has not been observed or recorded. The likely attack vector is remote: an adversary can deliver the malformed request over the network to any exposed HTTP interface that uses Netty for request decoding. The lack of proper chunk‑size validation enables request smuggling, which can lead to covert data exfiltration, privilege escalation, or service disruption, depending on how the target application handles subsequent requests.
OpenCVE Enrichment