Loading market data...
← Back to CVE feed

CVE-2026-93566

MEDIUM CVSS 6.5 View on NVD ↗

Description

A flaw was found in Netty. A remote attacker could exploit this by sending a specially crafted HTTP request that includes control characters within the chunk-size line. This bypasses the intended strict validation, allowing the attacker to inject arbitrary HTTP requests. This vulnerability can lead to HTTP request smuggling, potentially resulting in information disclosure or other unauthorized actions.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Published: Sep 18, 2026 15:17 UTC Modified: Sep 18, 2026 21:18 UTC