Netty HTTP request smuggling via chunked/Content-Length before 4.2.13.Final
CVE-2026-42581 Published on May 13, 2026
Netty: HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
Vulnerability Analysis
CVE-2026-42581 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. An automatable proof of concept (POC) exploit exists. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality and integrity, and no impact on availability.
Weakness Type
What is a HTTP Request Smuggling Vulnerability?
When malformed or abnormal HTTP requests are interpreted by one or more entities in the data flow between the user and the web server, such as a proxy or firewall, they can be interpreted inconsistently, allowing the attacker to "smuggle" a request to one device without the other device being aware of it.
CVE-2026-42581 has been classified to as a HTTP Request Smuggling vulnerability or weakness.
Products Associated with CVE-2026-42581
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2026-42581 are published in these products:
Affected Versions
netty:- Version >= 4.2.0.Alpha1, < 4.2.13.Final is affected.
- Version < 4.1.133.Final is affected.
- Version 4.2.0-10 and below * is unaffected.
- Version 4.2.0-10 and below * is unaffected.
- Version 4.2.0-10 and below * is unaffected.
- Version codec-http and below * is unaffected.
- Version codec-http and below * is unaffected.
- Version 1780948325 and below * is unaffected.
- Version 1780696380 and below * is unaffected.
- Version 1780694994 and below * is unaffected.
- Version 1782989027 and below * is unaffected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.