{"id":"CVE-2026-89044","summary":"Netty 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final HTTP Request Smuggling via Transfer-Encoding","details":"Netty versions 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final fail to properly validate the final transfer coding in the Transfer-Encoding header, allowing attackers to smuggle requests by using malformed encoding declarations. Attackers can split Transfer-Encoding headers across multiple lines or use values like 'chunked, xchunked' to bypass validation and decode messages as chunked when the final coding is not chunked, enabling request smuggling attacks.","aliases":["GHSA-hcvj-94mj-jp5c"],"modified":"2026-09-12T03:47:21.677317564Z","published":"2026-09-10T17:39:34.162Z","database_specific":{"cwe_ids":["CWE-444"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89044.json","cna_assigner":"VulnCheck"},"references":[{"type":"WEB","url":"https://repo1.maven.org/maven2/io/netty/netty-codec-http/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89044.json"},{"type":"ADVISORY","url":"https://github.com/netty/netty/releases/tag/netty-4.1.138.Final"},{"type":"ADVISORY","url":"https://github.com/netty/netty/releases/tag/netty-4.2.18.Final"},{"type":"ADVISORY","url":"https://github.com/netty/netty/security/advisories/GHSA-hcvj-94mj-jp5c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89044"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/netty-4.1.133-final-through-4.1.137-final-and-4.2.13-final-through-4.2.17-final-http-request-smuggling-via-transfer-encoding"},{"type":"FIX","url":"https://github.com/netty/netty/commit/640d4d3324f7b811a4903d0730c8ccb35500500c"},{"type":"FIX","url":"https://github.com/netty/netty/commit/ca87393b0e9e13c493d213a268e727a6d44e1585"},{"type":"PACKAGE","url":"https://github.com/netty/netty"},{"type":"ARTICLE","url":"https://github.com/netty/netty/blob/netty-4.1.137.Final/codec-http/src/main/java/io/netty/handler/codec/http/HttpObjectDecoder.java#L866"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/netty/netty","events":[{"introduced":"fb13125f135ab53203513ff603872a3abe84d38d"},{"fixed":"26e68a2c3935e459b374891c87760f6d6c5e2550"},{"introduced":"b3844c8108b42f68d56144b36d4d1ed96078a688"},{"fixed":"2521f494432e27415a567d3a81a9eb907abf20b3"}],"database_specific":{"extracted_events":[{"introduced":"4.1.133.Final"},{"fixed":"4.1.138.Final"},{"introduced":"4.2.13.Final"},{"fixed":"4.2.18.Final"}],"source":"AFFECTED_FIELD"}}],"versions":["netty-clang-bin","netty-4.1.137.Final","netty-4.2.17.Final","netty-4.1.136.Final","netty-4.2.16.Final","netty-4.1.135.Final","netty-4.2.15.Final","netty-4.1.134.Final","netty-4.2.14.Final","netty-4.1.133.Final","netty-4.2.13.Final"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89044.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"}]}