CVE-2026-33870

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/03/2026
Last modified:
30/03/2026

Description

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:* 4.1.132 (excluding)
cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:* 4.2.0 (including) 4.2.10 (excluding)