CVE-2020-7238

Publication date

2020-01-27 16:43:44

Family

mitre

State

PUBLISHED

Description

Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line) and a later Content-Length header. This issue exists because of an incomplete fix for CVE-2019-16869.