High severity7.5NVD Advisory· Published Jan 27, 2020· Updated Jun 17, 2026
CVE-2020-7238
CVE-2020-7238
Description
Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line) and a later Content-Length header. This issue exists because of an incomplete fix for CVE-2019-16869.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
io.netty:netty-handlerMaven | >= 4.1.43, < 4.1.45 | 4.1.45 |
Affected products
12- Netty/Nettydescription
- cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.2:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.2:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.3:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.4:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:jboss_enterprise_application_platform_text-only_advisories:-:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_application_runtimes_text-only_advisories:-:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
26- github.com/jdordonezn/CVE-2020-72381/issues/1nvdExploitThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2020:0497nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2020:0567nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2020:0601nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2020:0605nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2020:0606nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2020:0804nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2020:0805nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2020:0806nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2020:0811nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-ff2w-cq2g-wv5fghsaADVISORY
- lists.debian.org/debian-lts-announce/2020/02/msg00017.htmlnvdMailing ListThird Party AdvisoryWEB
- lists.debian.org/debian-lts-announce/2020/02/msg00018.htmlnvdMailing ListThird Party AdvisoryWEB
- lists.debian.org/debian-lts-announce/2020/09/msg00003.htmlnvdMailing ListThird Party AdvisoryWEB
- netty.io/news/nvdVendor Advisory
- nvd.nist.gov/vuln/detail/CVE-2020-7238ghsaADVISORY
- www.debian.org/security/2021/dsa-4885nvdThird Party AdvisoryWEB
- github.com/netty/netty/issues/9861ghsaWEB
- github.com/netty/netty/pull/9865ghsaWEB
- lists.apache.org/thread.html/r131e572d003914843552fa45c4398b9903fb74144986e8b107c0a3a7@%3Ccommits.cassandra.apache.org%3EghsaWEB
- lists.apache.org/thread.html/rc8d554aad889d12b140d9fd7d2d6fc2e8716e9792f6f4e4b2cdc2d05@%3Ccommits.cassandra.apache.org%3EghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/TS6VX7OMXPDJIU5LRGUAHRK6MENAVJ46ghsaWEB
- netty.io/newsghsaWEB
- lists.apache.org/thread.html/r131e572d003914843552fa45c4398b9903fb74144986e8b107c0a3a7%40%3Ccommits.cassandra.apache.org%3Envd
- lists.apache.org/thread.html/rc8d554aad889d12b140d9fd7d2d6fc2e8716e9792f6f4e4b2cdc2d05%40%3Ccommits.cassandra.apache.org%3Envd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TS6VX7OMXPDJIU5LRGUAHRK6MENAVJ46/nvd
News mentions
0No linked articles in our index yet.