Bug 2536951 (CVE-2026-93562) - CVE-2026-93562 io.netty/netty-codec-http: Netty: Incomplete validation of malformed Transfer-Encoding allows HTTP request smuggling
Summary: CVE-2026-93562 io.netty/netty-codec-http: Netty: Incomplete validation of mal...
Keywords:
Status: NEW
Alias: CVE-2026-93562
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-18 09:55 UTC by OSIDB Bzimport
Modified: 2026-09-18 20:01 UTC (History)
66 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-18 09:55:07 UTC
Incomplete validation of malformed Transfer-Encoding allows HTTP request smuggling

A public GitHub Security Advisory (GHSA-hcvj-94mj-jp5c) describes the following issue:

### Summary

Netty's HTTP/1 decoder still accepts some malformed `Transfer-Encoding` values where `chunked` is present but is not the final transfer coding.
This appears to be an incomplete fix / bypass of CVE-2026-42585 / GHSA-38f8-5428-x5cv. The canonical case `Transfer-Encoding: chunked, gzip` is rejected, but multi-line and pseudo-suffix variants are still accepted and decoded as chunked, which can lead to HTTP request smuggling in parser-differential deployments.

### Details

The issue is in `io.netty.handler.codec.http.HttpObjectDecoder#readHeaders`.

Current behavior uses two different checks:

- `HttpUtil.isTransferEncodingChunked(...)` detects an exact `chunked` token anywhere in any `Transfer-Encoding` field.
- `readHeaders(...)` then checks whether `chunked` is last by testing whether the last raw `Transfer-Encoding` field value ends with the string `chunked`.

This suffix check is not equivalent to parsing the final transfer-coding token.

Examples that are incorrectly accepted:

```
  Transfer-Encoding: chunked
  Transfer-Encoding: gzip
``` 
This is semantically equivalent to Transfer-Encoding: chunked, gzip, where chunked is not final.

Transfer-Encoding: chunked, xchunked

The final transfer coding is xchunked, not chunked, but the raw value ends with chunked.

RFC 9112 requires request messages where chunked is not the final transfer coding to be rejected with 400 and the connection closed.

### PoC
you can run this code
[TransferEncodingSmugglingReproducer.java](https://github.com/user-attachments/files/30192920/TransferEncodingSmugglingReproducer.java)

### Impact
HTTP Request Smuggling: Attacker injects arbitrary HTTP requests

 This can be used as the fix patch
[netty-te-final-token.patch](https://github.com/user-attachments/files/30194466/netty-te-final-token.patch)

Affected:
- maven:io.netty:netty-codec-http affected >=4.2.0.Final, <=4.2.17.Final; fixed unknown
- maven:io.netty:netty-codec-http affected <=4.1.137.Final; fixed unknown

Fixed versions: see advisory

Advisory: https://github.com/netty/netty/security/advisories/GHSA-hcvj-94mj-jp5c


Note You need to log in before you can comment on or make changes to this bug.