Vulnerabilities
Vulnerable Software
Netty:  >> Netty  >> 3.10.5  Security Vulnerabilities
HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.
CVSS Score
9.1
EPSS Score
0.027
Published
2020-01-29
Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling.
CVSS Score
7.5
EPSS Score
0.04
Published
2019-09-26


Contact Us

Shodan ® - All rights reserved