Back

HIGH

netty: HTTP request smuggling by mishandled whitespace before the colon in HTTP headers

Published Sep 26, 2019

Description

Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling.

Affected products

Remediation

Red Hat statement

OpenShift Container Platform ships a vulnerable netty library as part of the logging-elasticsearch5 container. ElasticSearch's security team has stated that this vulnerability does not poses a substantial practical threat to ElasticSearch 6 [1]. We agree that this issue would be difficult to exploit these vulnerabilities on OpenShift Container Platform, so we're reducing the impact of this issue to moderate and may fix it in the future release. Red Hat Satellite ships vulnerable netty version embedded in Candlepin, however, is not directly vulnerable since HTTP requests are handled by Tomcat and not netty. [1] https://github.com/elastic/elasticsearch/issues/49396

Red Hat mitigation

* Use HTTP/2 instead (clear boundaries between requests) * Disable reuse of backend connections eg. ```http-reuse never``` in HAProxy or whatever equivalent LB settings

Weaknesses (1)

References (152)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Sep 26, 2019
Updated Jul 7, 2025
Reserved Sep 25, 2019

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Important
Public date Sep 26, 2019
Bugzilla 1758619

ENISA EUVD

Assigner mitre
Published Sep 26, 2019
Updated Jul 7, 2025