Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29651
HistoryMar 10, 2021 - 5:52 a.m.

HTTP Request Smuggling

2021-03-1005:52:36
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
22
netty
http request smuggling
content-length
http/2
http/1.1

EPSS

0.186

Percentile

96.2%

netty-codec-http2 is vulnerable to HTTP request smuggling. The Content-Length header is not validated and allows an attacker to smuggle requests as requests are downgraded from HTTP/2 to HTTP/1.1.

References