
Find real vulnerabilities before they ship
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
Base Score
6.5| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| io.netty:netty-codec-http(Maven) | 4.2.0.Alpha1 | 4.2.13.Final | N/A |
| io.netty:netty-codec-http(Maven) | 0 | 4.1.133.Final | N/A |
| Base Score | 6.5 |
|---|---|
| Vector String | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |
| Base Severity | Medium |
| Version | 3.1 |
| Attack Vector (AV) | NETWORK |