Bug 2477214 (CVE-2026-42580) - CVE-2026-42580 netty: Netty: Request smuggling via chunk size parser integer overflow
Summary: CVE-2026-42580 netty: Netty: Request smuggling via chunk size parser integer ...
Keywords:
Status: NEW
Alias: CVE-2026-42580
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-13 19:01 UTC by OSIDB Bzimport
Modified: 2026-05-25 08:29 UTC (History)
109 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-05-13 19:01:35 UTC
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.


Note You need to log in before you can comment on or make changes to this bug.