Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling.
Update io.netty:netty-all to 4.1.42.Final if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanHTTP Request Smuggling in Netty affects io.netty:netty (maven), io.netty:netty-all (maven), org.jboss.netty:netty (maven). Severity is high. Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling.
AI coding agents often install or upgrade packages automatically in maven. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| io.netty:nettymaven | >=3.3.0.Final,<=4.0.0.Alpha8 | Not reported |
| io.netty:netty-allmaven |
Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling.
Update io.netty:netty-all to 4.1.42.Final if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanHTTP Request Smuggling in Netty affects io.netty:netty (maven), io.netty:netty-all (maven), org.jboss.netty:netty (maven). Severity is high. Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling.
AI coding agents often install or upgrade packages automatically in maven. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| io.netty:nettymaven | >=3.3.0.Final,<=4.0.0.Alpha8 | Not reported |
| io.netty:netty-allmaven |
| >=4.0.0.Beta1,<4.1.42.Final |
| 4.1.42.Final |
| org.jboss.netty:nettymaven | <=3.2.9.Final | Not reported |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| >=4.0.0.Beta1,<4.1.42.Final |
| 4.1.42.Final |
| org.jboss.netty:nettymaven | <=3.2.9.Final | Not reported |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard