Bug 2507480 (CVE-2026-59900)

Summary: CVE-2026-59900 io.netty/netty-codec-http2: Netty: Improper header neutralization in netty-codec-http2
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: aazores, abrianik, ant, anujha, aschwart, asoldano, asyoung, aszczucz, ataylor, avibelli, bbaranow, bbrownin, bgeorges, bmaxwell, boliveir, bstansbe, ccranfor, cescoffi, chfoley, cmah, dandread, dbruscin, dhanak, dkreling, dlofthou, drichtar, drosa, dsimansk, eaguilar, ebaron, ehugonne, ewittman, fmariani, fmongiar, ggrzybek, gmalinko, gsmet, gtanzill, istudens, ivassile, iweiss, janstey, jbuscemi, jhollowa, jmartisk, jmatsuok, jnethert, jpechane, jraez, jtolenti, jwon, kaycoth, kgaikwad, kingland, kvanderr, lthon, manderse, mcarlett, mnovotny, mosmerov, mposolda, msvehla, nipatil, nwallace, olubyans, pantinor, parichar, pberan, pesilva, pgallagh, pjindal, pmackay, prichard, probinso, rgodfrey, rguimara, rkubis, rmartinc, rruss, rstancel, rstepani, rsvoboda, sausingh, sbiarozk, sdawley, ssilvert, sthirugn, sthorger, swoodman, tasato, tcunning, thjenkin, tqvarnst, vdosoudi, vmuzikar, yfang
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Netty's netty-codec-http2 component. The HTTP/2 encoder does not properly handle special characters in HTTP headers. This vulnerability allows a remote attacker to craft specific HTTP/2 requests, leading to HTTP response splitting and header injection attacks. Such attacks can enable an attacker to manipulate web content or inject malicious headers.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-07-27 14:37:30 UTC
Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final, the HTTP/2 encoder in netty-codec-http2 fails to properly neutralize special characters in HTTP headers. An attacker can craft specially formed HTTP/2 requests that inject arbitrary header content, allowing HTTP response splitting and header injection attacks. This issue is fixed in versions 4.1.136.Final and later.