{"id":"CVE-2019-17513","details":"An issue was discovered in Ratpack before 1.7.5. Due to a misuse of the Netty library class DefaultHttpHeaders, there is no validation that headers lack HTTP control characters. Thus, if untrusted data is used to construct HTTP headers with Ratpack, HTTP Response Splitting can occur.","aliases":["GHSA-mvqp-q37c-wf9j"],"modified":"2026-07-09T01:25:58.575685Z","published":"2019-10-18T03:15:09.897Z","references":[{"type":"ADVISORY","url":"https://github.com/ratpack/ratpack/releases/tag/v1.7.5"},{"type":"ADVISORY","url":"https://github.com/ratpack/ratpack/security/advisories/GHSA-mvqp-q37c-wf9j"},{"type":"ADVISORY","url":"https://ratpack.io/versions/1.7.5"},{"type":"FIX","url":"https://github.com/ratpack/ratpack/commit/c560a8d10cb8bdd7a526c1ca2e67c8f224ca23ae"},{"type":"FIX","url":"https://github.com/ratpack/ratpack/commit/efb910d38a96494256f36675ef0e5061097dd77d"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ratpack/ratpack","events":[{"introduced":"0"},{"fixed":"02f8e6b9076eab03e9227b3ccbbdee952355f7b9"},{"fixed":"c560a8d10cb8bdd7a526c1ca2e67c8f224ca23ae"},{"fixed":"efb910d38a96494256f36675ef0e5061097dd77d"}],"database_specific":{"cpe":"cpe:2.3:a:ratpack_project:ratpack:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.7.5"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v1.7.4","v1.7.3","v1.7.2","v1.7.1","v1.7.0","v1.6.0","v1.6.0-rc-4","v1.6.0-rc-3","v1.6.0-rc-2","1.6.0-rc-1","v1.5.0","v1.5.0-rc-3","v1.5.0-rc-1","v1.4.0","v1.4.0-rc-3","v1.4.0-rc-2","v1.4.0-rc-1","v1.3.1","v1.3.0","v1.3.0-rc-2","v1.3.0-rc-1","v1.2.0","v1.2.0-rc-2","v1.2.0-RC-1","v1.1.1","v1.1.0","v1.0.0","v1.0.0-rc-3","v1.0.0-rc-2","v1.0.0-rc-1","v0.9.19","v0.9.18","v0.9.17","v0.9.16","v0.9.15","v0.9.14","v0.9.13","v0.9.12","v0.9.11","v0.9.10","v0.9.9","v0.9.8","v0.9.7","v0.9.6","v0.9.5","v0.9.4","v0.9.3","v0.9.2","v0.9.1","v0.9.0","0.6.1","0.5.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-17513.json","vanir_signatures_modified":"2026-07-09T01:25:58Z","vanir_signatures":[{"digest":{"length":2737,"function_hash":"316688032063787779101292422721492487926"},"id":"CVE-2019-17513-58fd1cb3","signature_type":"Function","signature_version":"v1","source":"https://github.com/ratpack/ratpack/commit/efb910d38a96494256f36675ef0e5061097dd77d","target":{"file":"ratpack-core/src/main/java/ratpack/server/internal/NettyHandlerAdapter.java","function":"newRequest"},"deprecated":false},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/ratpack/ratpack/commit/efb910d38a96494256f36675ef0e5061097dd77d","target":{"file":"ratpack-core/src/main/java/ratpack/server/internal/NettyHandlerAdapter.java"},"deprecated":false,"digest":{"line_hashes":["314384977944997157326766606166716536607","299455186994735692910888951443078280123","306215249784964445081505597330082683274","94291133209474141190259058947212806303"],"threshold":0.9},"id":"CVE-2019-17513-b3a1caf4"}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}