Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33238
HistoryDec 10, 2021 - 7:49 a.m.

HTTP Request Smuggling

2021-12-1007:49:39
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
32

0.002 Low

EPSS

Percentile

62.3%

io.netty:netty-codec-http is vulnerable to HTTP request smuggling. Improper validation of control chars, when they are present at the beginning and/or end of the header name leads to HTTP request smuggling which allows an attacker to exploit other remote systems when these headers are used as a proxy.