A flaw was found in Netty before version 4.1.44, where it accepted multiple Content-Length headers and also accepted both Transfer-Encoding, as well as Content-Length headers where it should reject the message under such circumstances. In circumstances where Netty is used in the context of a server, it could result in a viable HTTP smuggling vulnerability.
Other sources
A vulnerability was found in HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.
Netty could provide weaker than expected security, caused by non-proper handling of Content-Length and Transfer-Encoding in the HttpObjectDecoder.java. A remote attacker could exploit this vulnerability to launch further attacks on the system.
* Use HTTP/2 instead (clear boundaries between requests)
* Disable reuse of backend connections eg. ```http-reuse never``` in HAProxy or whatever equivalent LB settings
Event History
Jan 29, 2020
CVE Published
12:00 AM
CVE Published
via MITRE·08:33 PM
Data Sourced
via MITRE·08:33 PM
Description
Feb 5, 2020
Data Sourced
via Red Hat·02:20 PM
DescriptionSeverityAffected Software
Feb 21, 2020
Advisory Published
06:55 PM
Aug 15, 2025
Data Sourced
via IBM·03:29 PM
DescriptionAffected Software
Feb 23, 2026
Data Sourced
via Ubuntu·03:18 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·03:19 PM
Description
Data Sourced
via Debian·03:19 PM
DescriptionAffected Software
Parent advisories
This vulnerability appears in the following advisories.
SecAlerts Pty Ltd. 132 Wickham Terrace Fortitude Valley, QLD 4006, Australia info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.