Impact
A flaw in Netty’s HTTP/1.1 decoder (CWE‑444) allows an attacker to split the Transfer‑Encoding header across multiple fields, bypassing final‑chunked validation; this can be used to smuggle one HTTP request inside another, potentially leading to unauthorized request handling, privilege escalation or denial of service.
Affected Systems
Affected Red Hat products include AMQ Broker 7, AMQ Clients, build of Keycloak, Data Grid 8, Fuse 7, JBoss Enterprise Application Platform 7/8, Single Sign‑On 7, build of Apache Camel 4 for Quarkus 3, build of Apache Camel for Spring Boot 4, Apicurio Registry 3, Debezium 3, and Quarkus 3. No specific version ranges are listed in the CVE data, so it is inferred that any deployment using the affected Netty library version is potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.5 places the issue in the moderate severity range. EPSS indicates a low exploitation probability of less than 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known public exploits. The likely attack vector is inferred to be remote network access, as the description states that a remote attacker can send crafted HTTP traffic to the target service to perform the split Transfer‑Encoding technique. Successful exploitation could mislead the server into processing a smuggled request, allowing privilege escalation, data tampering or denial of service.
OpenCVE Enrichment