Description
Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling.
Remediation
References
Related Vulnerabilities
Undertow Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2020-1745)
OpenSSL Out-of-bounds Read Vulnerability (CVE-2023-1255)
WordPress Weak Password Recovery Mechanism for Forgotten Password Vulnerability (CVE-2017-8295)
PHP Use of Uninitialized Resource Vulnerability (CVE-2015-8390)