Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line) and a later Content-Length header. This issue exists because of an incomplete fix for CVE-2019-16869.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| io.netty:netty-handler(Maven) | 4.1.43 | 4.1.45 | N/A |
CVSS Metrics