Source: netty Version: 1:4.1.48-16 Severity: grave Tags: security upstream Justification: user security hole X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerabilities were published for netty. CVE-2026-76816[0]: | Netty is an asynchronous, event-driven network application | framework. Prior to versions 4.1.137.Final and 4.2.17.Final, | MqttEncoder does not validate client identifiers, will topics, | usernames, and PUBLISH topic names before encoding, allowing | prohibited null bytes in MQTT UTF-8 string fields and potentially | causing routing, access-control, or identity mismatches in | downstream brokers. The vulnerability is exploitable when an | application uses Netty's MQTT encoder to construct messages from | user-controlled input. This issue is fixed in versions 4.1.137.Final | and 4.2.17.Final. CVE-2026-89044[1]: | Netty versions 4.1.133.Final through 4.1.137.Final and 4.2.13.Final | through 4.2.17.Final fail to properly validate the final transfer | coding in the Transfer-Encoding header, allowing attackers to | smuggle requests by using malformed encoding declarations. Attackers | can split Transfer-Encoding headers across multiple lines or use | values like 'chunked, xchunked' to bypass validation and decode | messages as chunked when the final coding is not chunked, enabling | request smuggling attacks. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-76816 https://www.cve.org/CVERecord?id=CVE-2026-76816 [1] https://security-tracker.debian.org/tracker/CVE-2026-89044 https://www.cve.org/CVERecord?id=CVE-2026-89044 Regards, Salvatore

