Impact
A flaw was discovered in Netty's netty-codec-http component where the HTTP/1.1 chunk-size token is parsed incorrectly when post‑digit whitespace is present. This parsing error can be exploited by a remote attacker to perform HTTP request smuggling, allowing the smuggled request to bypass upstream security controls, reach protected backend services, or expose unauthorized resources. The weakness stems from improper validation of the chunk‑size token (CWE‑444).
Affected Systems
The vulnerability affects a range of Red Hat products that embed Netty, including Red Hat AMQ Broker 7, Red Hat AMQ Clients, Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7 and 8, Red Hat Single Sign‑On 7, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apache Camel for Spring Boot 4, Red Hat build of Apicurio Registry 3, Red Hat build of Debezium 3, and Red Hat build of Quarkus 3. No specific affected versions are listed in the CVE data.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity vulnerability, primarily impacting integrity and confidentiality through request smuggling. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not a currently exploited or widely monitored issue. The likely attack vector is remote, involving a specially crafted HTTP request sent over a network connection to a Netty‑powered service. Exploitation requires no local privileges and can be performed from outside the host, potentially allowing an adversary to bypass security layers or access protected resources in a proxy or backend deployment.
OpenCVE Enrichment