CVE-2019-16869 PUBLISHED

Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling.

EPSS 4.03% · 88.4th percentile

Risk Scores

EPSS Score
4.03%
88.4th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSnetty-3.90, 3.9.0.Final-1
Ubuntu:Pro:14.04:LTSnetty1:3.2.6.Final-2, 0
Ubuntu:18.04:LTSnetty-3.90, 3.9.9.Final-1
Ubuntu:Pro:16.04:LTSnetty1:4.0.34-1ubuntu0.1~esm1, 1:4.0.34-1ubuntu0.1~esm2, 1:4.0.34-1ubuntu0.1~esm3
Ubuntu:Pro:18.04:LTSnetty0, 1:4.1.7-4, 1:4.1.7-4ubuntu0.1~esm1

Timeline

References

Open in Interactive Console →