Source: netty
Version: 1:4.1.48-16
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for netty.

CVE-2026-76816[0]:
| Netty is an asynchronous, event-driven network application
| framework. Prior to versions 4.1.137.Final and 4.2.17.Final,
| MqttEncoder does not validate client identifiers, will topics,
| usernames, and PUBLISH topic names before encoding, allowing
| prohibited null bytes in MQTT UTF-8 string fields and potentially
| causing routing, access-control, or identity mismatches in
| downstream brokers. The vulnerability is exploitable when an
| application uses Netty's MQTT encoder to construct messages from
| user-controlled input. This issue is fixed in versions 4.1.137.Final
| and 4.2.17.Final.


CVE-2026-89044[1]:
| Netty versions 4.1.133.Final through 4.1.137.Final and 4.2.13.Final
| through 4.2.17.Final fail to properly validate the final transfer
| coding in the Transfer-Encoding header, allowing attackers to
| smuggle requests by using malformed encoding declarations. Attackers
| can split Transfer-Encoding headers across multiple lines or use
| values like 'chunked, xchunked' to bypass validation and decode
| messages as chunked when the final coding is not chunked, enabling
| request smuggling attacks.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-76816
    https://www.cve.org/CVERecord?id=CVE-2026-76816
[1] https://security-tracker.debian.org/tracker/CVE-2026-89044
    https://www.cve.org/CVERecord?id=CVE-2026-89044

Regards,
Salvatore

Reply via email to