View all vulnerabilities

CVE-2019-20445

HTTP Request Smuggling in Netty

HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.

Patch Available

Fix available through Seal Security. No upgrade required, protect your application instantly.

Fix without upgrading
Vulnerability Details
Score
Score Vector
Affected Versions
io.netty:netty-handler >= 4.0.0 < 4.1.45
Severity
Ecosystem
Publish Date
February 21, 2020
Modified Date
December 8, 2024