Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29869
HistoryMar 31, 2021 - 4:38 a.m.

HTTP Request Smuggling

2021-03-3104:38:02
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
23
vulnerability
incomplete fix
cve-2021-21295
content-length
validation
http2headerframe
endstream
netty-codec-http2

EPSS

0.186

Percentile

96.2%

netty-codec-http2 is vulnerable to HTTP request smuggling. The vulnerability exists through an incomplete fix in CVE-2021-21295 where the content-length header is not properly validated if the request uses a single Http2HeaderFrame, and with endStream set to true.

References