CVE-2019-20444 PUBLISHED

HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an "invalid fold."

EPSS 11.10% · 93.4th percentile

Risk Scores

EPSS Score
11.10%
93.4th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSnetty-3.90, 3.9.9.Final-1
Ubuntu:16.04:LTSnetty-3.93.9.0.Final-1, 0
Ubuntu:Pro:14.04:LTSnetty0, 1:3.2.6.Final-2
Ubuntu:18.04:LTSnetty0, 1:4.1.7-4
Ubuntu:Pro:16.04:LTSnetty1:4.0.34-1ubuntu0.1~esm3, 0, 1:3.2.6.Final-2

Timeline

References

Open in Interactive Console →