PT-2026-28107 · Netty+2 · Netty+2

·

CVE-2026-33870

·

Published

2026-03-24

·

Updated

2026-07-22

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Netty versions prior to 4.1.132.Final and 4.2.10.Final
Description Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Specifically, Netty terminates chunk header parsing at carriage return/newline characters within quoted strings instead of rejecting the request as malformed. This creates a parsing differential between Netty and RFC-compliant parsers. The root cause is that Netty does not validate that carriage return/line feed bytes are forbidden inside chunk extensions before the terminating carriage return/line feed. A request containing carriage return/line feed bytes within a chunk extension value should be rejected outright as invalid. This issue can lead to request smuggling, cache poisoning, access control bypass, and session hijacking.
Recommendations Update to Netty version 4.1.132.Final or 4.2.10.Final.

Exploit

Fix

DoS

HTTP Request/Response Smuggling

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09557
CLEANSTART-2026-AV84730
CLEANSTART-2026-BK55944
CLEANSTART-2026-CF62516
CLEANSTART-2026-CP46043
CLEANSTART-2026-CQ39708
CLEANSTART-2026-DD05788
CLEANSTART-2026-DV49899
CLEANSTART-2026-DY69070
CLEANSTART-2026-EZ90321
CLEANSTART-2026-FV79231
CLEANSTART-2026-FX60287
CLEANSTART-2026-FZ22182
CLEANSTART-2026-GN46454
CLEANSTART-2026-IE61882
CLEANSTART-2026-IS05941
CLEANSTART-2026-IY44515
CLEANSTART-2026-JU62349
CLEANSTART-2026-KB76878
CLEANSTART-2026-KL03760
CLEANSTART-2026-LB41442
CLEANSTART-2026-LE11246
CLEANSTART-2026-MT41286
CLEANSTART-2026-MX76059
CLEANSTART-2026-NE94194
CLEANSTART-2026-NW12954
CLEANSTART-2026-OI70918
CLEANSTART-2026-OQ84658
CLEANSTART-2026-PM36304
CLEANSTART-2026-RN56220
CLEANSTART-2026-RS65756
CLEANSTART-2026-RU36468
CLEANSTART-2026-SH44648
CLEANSTART-2026-SQ91016
CLEANSTART-2026-SR31778
CLEANSTART-2026-SV95049
CLEANSTART-2026-TK07726
CLEANSTART-2026-VH41554
CLEANSTART-2026-VJ37814
CLEANSTART-2026-VN28553
CLEANSTART-2026-WG59699
CLEANSTART-2026-WK99982
CLEANSTART-2026-WT54034
CLEANSTART-2026-YX54699
CLEANSTART-2026-YY96069
CVE-2026-33870
GHSA-PWQR-WMGM-9RR8
OPENSUSE-SU-2026:10463-1
RHSA-2026:18054
RHSA-2026:18055
SUSE-SU-2026:1353-1

Affected Products

Confluence
Netty
Red Os