CVE-2019-20445: Critical severity Netty Netty vulnerability

Published Jan 29, 2020
·
Updated

A flaw was found in Netty before version 4.1.44, where it accepted multiple Content-Length headers and also accepted both Transfer-Encoding, as well as Content-Length headers where it should reject the message under such circumstances. In circumstances where Netty is used in the context of a server, it could result in a viable HTTP smuggling vulnerability.

Other sources

A vulnerability was found in HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.

Reference: https://github.com/netty/netty/compare/netty-4.1.43.Final...netty-4.1.44.Final https://github.com/netty/netty/issues/9861 https://lists.apache.org/thread.html/r310d2ce22304d5298ff87f10134f918c87919b452734f9841d95682d@%3Ccommits.zookeeper.apache.org%3E https://lists.apache.org/thread.html/r36fcf538b28f2029e8b4f6b9a772f3b107913a78f09b095c5b153a62@%3Cissues.zookeeper.apache.org%3E https://lists.apache.org/thread.html/r640eb9b3213058a963e18291f903fc1584e577f60035f941e32f760a@%3Cissues.zookeeper.apache.org%3E https://lists.apache.org/thread.html/r70b1ff22ee80e8101805b9a473116dd33265709007d2deb6f8c80bf2@%3Ccommits.druid.apache.org%3E https://lists.apache.org/thread.html/r804895eedd72c9ec67898286eb185e04df852b0dd5fe53cf5b6138f9@%3Cissues.zookeeper.apache.org%3E https://lists.apache.org/thread.html/r81700644754e66ffea465c869cb477de25f8041e21598e8818fc2c45@%3Cdev.zookeeper.apache.org%3E https://lists.apache.org/thread.html/r96e08f929234e8ba1ef4a93a0fd2870f535a1f9ab628fabc46115986@%3Cdev.zookeeper.apache.org%3E https://lists.apache.org/thread.html/r9b20cdac704cf9a583400350e2d5b576fa8417c18ddb961201676c60@%3Ccommits.zookeeper.apache.org%3E https://lists.apache.org/thread.html/ra2ace4bcb5cf487f72cbcbfa0f8cc08e755ec2b93d7e69f276148b08@%3Cissues.zookeeper.apache.org%3E https://lists.apache.org/thread.html/ra9fbfe7d4830ae675bf34c7c0f8c22fc8a4099f65706c1bc4f54c593@%3Cissues.zookeeper.apache.org%3E https://lists.apache.org/thread.html/rce71d33747010d32d31d90f5d737dae26291d96552f513a266c92fbb@%3Cnotifications.zookeeper.apache.org%3E https://lists.apache.org/thread.html/re45ee9256d3233c31d78e59ee59c7dc841c7fbd83d0769285b41e948@%3Ccommits.druid.apache.org%3E https://lists.apache.org/thread.html/rfb55f245b08d8a6ec0fb4dc159022227cd22de34c4419c2fbb18802b@%3Cnotifications.zookeeper.apache.org%3E https://lists.apache.org/thread.html/rff210a24f3a924829790e69eaefa84820902b7b31f17c3bf2def9114@%3Ccommits.druid.apache.org%3E

Red Hat

Netty could provide weaker than expected security, caused by non-proper handling of Content-Length and Transfer-Encoding in the HttpObjectDecoder.java. A remote attacker could exploit this vulnerability to launch further attacks on the system.

IBM

Affected Software

110 affected componentsFixes available
maven/io.netty:netty<4.0.0
maven/org.jboss.netty:netty<4.0.0
maven/io.netty:netty-handler>=4.0.0<4.1.45
4.1.45
redhat/qpid-proton<0:0.30.0-4.el6_10
0:0.30.0-4.el6_10
redhat/qpid-proton<0:0.30.0-2.el7
0:0.30.0-2.el7
redhat/nodejs-rhea<0:1.0.16-1.el8
0:1.0.16-1.el8
redhat/qpid-proton<0:0.30.0-3.el8
0:0.30.0-3.el8
redhat/eap7-netty<0:4.1.45-1.Final_redhat_00001.1.el6ea
0:4.1.45-1.Final_redhat_00001.1.el6ea
redhat/eap7-activemq-artemis<0:2.9.0-2.redhat_00009.1.el6ea
0:2.9.0-2.redhat_00009.1.el6ea
redhat/eap7-apache-commons-beanutils<0:1.9.4-1.redhat_00002.1.el6ea
0:1.9.4-1.redhat_00002.1.el6ea
redhat/eap7-glassfish-el<0:3.0.1-4.b08_redhat_00003.1.el6ea
0:3.0.1-4.b08_redhat_00003.1.el6ea
redhat/eap7-glassfish-jaxb<0:2.3.3-4.b02_redhat_00001.1.el6ea
0:2.3.3-4.b02_redhat_00001.1.el6ea
redhat/eap7-glassfish-jsf<0:2.3.5-7.SP3_redhat_00005.1.el6ea
0:2.3.5-7.SP3_redhat_00005.1.el6ea
redhat/eap7-hal-console<0:3.0.20-1.Final_redhat_00001.1.el6ea
0:3.0.20-1.Final_redhat_00001.1.el6ea
redhat/eap7-hibernate<0:5.3.15-1.Final_redhat_00001.1.el6ea
0:5.3.15-1.Final_redhat_00001.1.el6ea
redhat/eap7-infinispan<0:9.3.8-1.Final_redhat_00001.1.el6ea
0:9.3.8-1.Final_redhat_00001.1.el6ea
redhat/eap7-ironjacamar<0:1.4.20-1.Final_redhat_00001.1.el6ea
0:1.4.20-1.Final_redhat_00001.1.el6ea
redhat/eap7-jackson-databind<0:2.9.10.2-1.redhat_00001.1.el6ea
0:2.9.10.2-1.redhat_00001.1.el6ea
redhat/eap7-jaegertracing-jaeger-client-java<0:0.34.1-1.redhat_00002.1.el6ea
0:0.34.1-1.redhat_00002.1.el6ea
redhat/eap7-jboss-ejb-client<0:4.0.28-1.Final_redhat_00001.1.el6ea
0:4.0.28-1.Final_redhat_00001.1.el6ea
redhat/eap7-jboss-remoting<0:5.0.17-1.Final_redhat_00001.1.el6ea
0:5.0.17-1.Final_redhat_00001.1.el6ea
redhat/eap7-jboss-server-migration<0:1.3.1-8.Final_redhat_00009.1.el6ea
0:1.3.1-8.Final_redhat_00009.1.el6ea
redhat/eap7-picketlink-bindings<0:2.5.5-23.SP12_redhat_00012.1.el6ea
0:2.5.5-23.SP12_redhat_00012.1.el6ea
redhat/eap7-stax2-api<0:4.2.0-1.redhat_00001.1.el6ea
0:4.2.0-1.redhat_00001.1.el6ea
redhat/eap7-sun-istack-commons<0:3.0.10-1.redhat_00001.1.el6ea
0:3.0.10-1.redhat_00001.1.el6ea
redhat/eap7-thrift<0:0.13.0-1.redhat_00002.1.el6ea
0:0.13.0-1.redhat_00002.1.el6ea
redhat/eap7-wildfly<0:7.2.7-4.GA_redhat_00004.1.el6ea
0:7.2.7-4.GA_redhat_00004.1.el6ea
redhat/eap7-wildfly-http-client<0:1.0.20-1.Final_redhat_00001.1.el6ea
0:1.0.20-1.Final_redhat_00001.1.el6ea
redhat/eap7-wildfly-openssl<0:1.0.9-2.SP03_redhat_00001.1.el6ea
0:1.0.9-2.SP03_redhat_00001.1.el6ea
redhat/eap7-wildfly-transaction-client<0:1.1.9-1.Final_redhat_00001.1.el6ea
0:1.1.9-1.Final_redhat_00001.1.el6ea
redhat/eap7-woodstox-core<0:6.0.3-1.redhat_00001.1.el6ea
0:6.0.3-1.redhat_00001.1.el6ea
redhat/eap7-xml-security<0:2.1.4-1.redhat_00001.1.el6ea
0:2.1.4-1.redhat_00001.1.el6ea
redhat/eap7-netty<0:4.1.45-1.Final_redhat_00001.1.el7ea
0:4.1.45-1.Final_redhat_00001.1.el7ea
redhat/eap7-activemq-artemis<0:2.9.0-2.redhat_00009.1.el7ea
0:2.9.0-2.redhat_00009.1.el7ea
redhat/eap7-apache-commons-beanutils<0:1.9.4-1.redhat_00002.1.el7ea
0:1.9.4-1.redhat_00002.1.el7ea
redhat/eap7-glassfish-el<0:3.0.1-4.b08_redhat_00003.1.el7ea
0:3.0.1-4.b08_redhat_00003.1.el7ea
redhat/eap7-glassfish-jaxb<0:2.3.3-4.b02_redhat_00001.1.el7ea
0:2.3.3-4.b02_redhat_00001.1.el7ea
redhat/eap7-glassfish-jsf<0:2.3.5-7.SP3_redhat_00005.1.el7ea
0:2.3.5-7.SP3_redhat_00005.1.el7ea
redhat/eap7-hal-console<0:3.0.20-1.Final_redhat_00001.1.el7ea
0:3.0.20-1.Final_redhat_00001.1.el7ea
redhat/eap7-hibernate<0:5.3.15-1.Final_redhat_00001.1.el7ea
0:5.3.15-1.Final_redhat_00001.1.el7ea
redhat/eap7-infinispan<0:9.3.8-1.Final_redhat_00001.1.el7ea
0:9.3.8-1.Final_redhat_00001.1.el7ea
redhat/eap7-ironjacamar<0:1.4.20-1.Final_redhat_00001.1.el7ea
0:1.4.20-1.Final_redhat_00001.1.el7ea
redhat/eap7-jackson-databind<0:2.9.10.2-1.redhat_00001.1.el7ea
0:2.9.10.2-1.redhat_00001.1.el7ea
redhat/eap7-jaegertracing-jaeger-client-java<0:0.34.1-1.redhat_00002.1.el7ea
0:0.34.1-1.redhat_00002.1.el7ea
redhat/eap7-jboss-ejb-client<0:4.0.28-1.Final_redhat_00001.1.el7ea
0:4.0.28-1.Final_redhat_00001.1.el7ea
redhat/eap7-jboss-remoting<0:5.0.17-1.Final_redhat_00001.1.el7ea
0:5.0.17-1.Final_redhat_00001.1.el7ea
redhat/eap7-jboss-server-migration<0:1.3.1-8.Final_redhat_00009.1.el7ea
0:1.3.1-8.Final_redhat_00009.1.el7ea
redhat/eap7-picketlink-bindings<0:2.5.5-23.SP12_redhat_00012.1.el7ea
0:2.5.5-23.SP12_redhat_00012.1.el7ea
redhat/eap7-stax2-api<0:4.2.0-1.redhat_00001.1.el7ea
0:4.2.0-1.redhat_00001.1.el7ea
redhat/eap7-sun-istack-commons<0:3.0.10-1.redhat_00001.1.el7ea
0:3.0.10-1.redhat_00001.1.el7ea
redhat/eap7-thrift<0:0.13.0-1.redhat_00002.1.el7ea
0:0.13.0-1.redhat_00002.1.el7ea
redhat/eap7-wildfly<0:7.2.7-4.GA_redhat_00004.1.el7ea
0:7.2.7-4.GA_redhat_00004.1.el7ea
redhat/eap7-wildfly-http-client<0:1.0.20-1.Final_redhat_00001.1.el7ea
0:1.0.20-1.Final_redhat_00001.1.el7ea
redhat/eap7-wildfly-openssl<0:1.0.9-2.SP03_redhat_00001.1.el7ea
0:1.0.9-2.SP03_redhat_00001.1.el7ea
redhat/eap7-wildfly-transaction-client<0:1.1.9-1.Final_redhat_00001.1.el7ea
0:1.1.9-1.Final_redhat_00001.1.el7ea
redhat/eap7-woodstox-core<0:6.0.3-1.redhat_00001.1.el7ea
0:6.0.3-1.redhat_00001.1.el7ea
redhat/eap7-xml-security<0:2.1.4-1.redhat_00001.1.el7ea
0:2.1.4-1.redhat_00001.1.el7ea
redhat/eap7-netty<0:4.1.45-1.Final_redhat_00001.1.el8ea
0:4.1.45-1.Final_redhat_00001.1.el8ea
redhat/eap7-activemq-artemis<0:2.9.0-2.redhat_00009.1.el8ea
0:2.9.0-2.redhat_00009.1.el8ea
redhat/eap7-apache-commons-beanutils<0:1.9.4-1.redhat_00002.1.el8ea
0:1.9.4-1.redhat_00002.1.el8ea
redhat/eap7-glassfish-el<0:3.0.1-4.b08_redhat_00003.1.el8ea
0:3.0.1-4.b08_redhat_00003.1.el8ea
redhat/eap7-glassfish-jaxb<0:2.3.3-4.b02_redhat_00001.1.el8ea
0:2.3.3-4.b02_redhat_00001.1.el8ea
redhat/eap7-glassfish-jsf<0:2.3.5-7.SP3_redhat_00005.1.el8ea
0:2.3.5-7.SP3_redhat_00005.1.el8ea
redhat/eap7-hal-console<0:3.0.20-1.Final_redhat_00001.1.el8ea
0:3.0.20-1.Final_redhat_00001.1.el8ea
redhat/eap7-hibernate<0:5.3.15-1.Final_redhat_00001.1.el8ea
0:5.3.15-1.Final_redhat_00001.1.el8ea
redhat/eap7-infinispan<0:9.3.8-1.Final_redhat_00001.1.el8ea
0:9.3.8-1.Final_redhat_00001.1.el8ea
redhat/eap7-ironjacamar<0:1.4.20-1.Final_redhat_00001.1.el8ea
0:1.4.20-1.Final_redhat_00001.1.el8ea
redhat/eap7-jackson-databind<0:2.9.10.2-1.redhat_00001.1.el8ea
0:2.9.10.2-1.redhat_00001.1.el8ea
redhat/eap7-jaegertracing-jaeger-client-java<0:0.34.1-1.redhat_00002.1.el8ea
0:0.34.1-1.redhat_00002.1.el8ea
redhat/eap7-jboss-ejb-client<0:4.0.28-1.Final_redhat_00001.1.el8ea
0:4.0.28-1.Final_redhat_00001.1.el8ea
redhat/eap7-jboss-remoting<0:5.0.17-1.Final_redhat_00001.1.el8ea
0:5.0.17-1.Final_redhat_00001.1.el8ea
redhat/eap7-jboss-server-migration<0:1.3.1-8.Final_redhat_00009.1.el8ea
0:1.3.1-8.Final_redhat_00009.1.el8ea
redhat/eap7-picketlink-bindings<0:2.5.5-23.SP12_redhat_00012.1.el8ea
0:2.5.5-23.SP12_redhat_00012.1.el8ea
redhat/eap7-stax2-api<0:4.2.0-1.redhat_00001.1.el8ea
0:4.2.0-1.redhat_00001.1.el8ea
redhat/eap7-sun-istack-commons<0:3.0.10-1.redhat_00001.1.el8ea
0:3.0.10-1.redhat_00001.1.el8ea
redhat/eap7-thrift<0:0.13.0-1.redhat_00002.1.el8ea
0:0.13.0-1.redhat_00002.1.el8ea
redhat/eap7-wildfly<0:7.2.7-4.GA_redhat_00004.1.el8ea
0:7.2.7-4.GA_redhat_00004.1.el8ea
redhat/eap7-wildfly-http-client<0:1.0.20-1.Final_redhat_00001.1.el8ea
0:1.0.20-1.Final_redhat_00001.1.el8ea
redhat/eap7-wildfly-openssl<0:1.0.9-2.SP03_redhat_00001.1.el8ea
0:1.0.9-2.SP03_redhat_00001.1.el8ea
redhat/eap7-wildfly-transaction-client<0:1.1.9-1.Final_redhat_00001.1.el8ea
0:1.1.9-1.Final_redhat_00001.1.el8ea
redhat/eap7-woodstox-core<0:6.0.3-1.redhat_00001.1.el8ea
0:6.0.3-1.redhat_00001.1.el8ea
redhat/eap7-xml-security<0:2.1.4-1.redhat_00001.1.el8ea
0:2.1.4-1.redhat_00001.1.el8ea
Netty Netty<4.1.44
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Fedoraproject Fedora=33
Canonical Ubuntu Linux=18.04
All of the following
Any of the following
redhat Jboss Amq Clients=2
redhat JBoss Enterprise Application Platform=7.2
redhat JBoss Enterprise Application Platform=7.3
Any of the following
redhat Enterprise Linux=6.0
redhat Enterprise Linux=7.0
redhat Enterprise Linux=8.0
Apache Spark=2.4.7
Apache Spark=2.4.8
redhat Jboss Amq Clients=2
redhat JBoss Enterprise Application Platform=7.2
redhat JBoss Enterprise Application Platform=7.3
redhat Enterprise Linux=6.0
redhat Enterprise Linux=7.0
redhat Enterprise Linux=8.0
redhat/netty<4.1.44
4.1.44
IBM Data Virtualization on Cloud Pak for Data<=3.0
IBM Watson Query on Cloud Pak for Data<=2.2
IBM Watson Query on Cloud Pak for Data<=2.1
IBM Watson Query on Cloud Pak for Data<=2.0
IBM Data Virtualization on Cloud Pak for Data<=1.8
IBM Data Virtualization on Cloud Pak for Data<=1.7
debian/netty
1:4.1.48-4+deb11u21:4.1.48-7+deb12u11:4.1.48-101:4.1.48-16

Remediation

Information

* Use HTTP/2 instead (clear boundaries between requests) * Disable reuse of backend connections eg. ```http-reuse never``` in HAProxy or whatever equivalent LB settings

Event History

Jan 29, 2020
CVE Published
12:00 AM
CVE Published
via MITRE·08:33 PM
Data Sourced
via MITRE·08:33 PM
Description
Feb 5, 2020
Data Sourced
via Red Hat·02:20 PM
DescriptionSeverityAffected Software
Feb 21, 2020
Advisory Published
06:55 PM
Aug 15, 2025
Data Sourced
via IBM·03:29 PM
DescriptionAffected Software
Feb 23, 2026
Data Sourced
via Ubuntu·03:18 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·03:19 PM
Description
Data Sourced
via Debian·03:19 PM
DescriptionAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2019-20445?

The CVE-2019-20445 vulnerability is considered high severity due to its potential to allow HTTP request smuggling attacks.

2

How do I fix CVE-2019-20445?

To resolve CVE-2019-20445, upgrade to Netty version 4.1.45 or later.

3

Which versions of Netty are affected by CVE-2019-20445?

Netty versions prior to 4.1.45 are affected by CVE-2019-20445.

4

What kind of attacks can CVE-2019-20445 facilitate?

CVE-2019-20445 can facilitate HTTP request smuggling attacks due to improper handling of multiple Content-Length headers.

5

Is there a workaround for CVE-2019-20445 until I can update?

There are no officially recommended workarounds for CVE-2019-20445; updating to a safe version is advised.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203