HTTP Request Smuggling in Netty
Critical severity
GitHub Reviewed
Published
Feb 21, 2020
to the GitHub Advisory Database
•
Updated Aug 16, 2023
Description
Published by the National Vulnerability Database
Jan 29, 2020
Reviewed
Feb 20, 2020
Published to the GitHub Advisory Database
Feb 21, 2020
Last updated
Aug 16, 2023
HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an "invalid fold."
References