Impact
Affected Netty HTTP codecs can mishandle ambiguous request framing when they parse malformed headers behind a proxy, load balancer, or cache [S1][S2]. In deployments where Netty receives untrusted HTTP traffic behind an intermediary, parser disagreement can lead to request desynchronization, security-control bypass, or cache poisoning.
Root Cause
CVE-2019-16869 affects Netty releases before the fixed 4.1.42.Final line and related legacy Maven coordinates [S1][S2]. The issue is tied to how affected HTTP parsing code treats malformed header whitespace, which can make Netty and an upstream intermediary disagree about where one request ends and the next begins.
FixVibe Coverage
FixVibe's GitHub repo scans flag Maven and Gradle projects that depend on Netty versions associated with CVE-2019-16869 / GHSA-p979-4mfw-53vg, with the dependency file, package coordinate and version.
Fix
Upgrade io.netty:netty-all to 4.1.42.Final or newer, or migrate legacy io.netty:netty / org.jboss.netty:netty usage to a maintained fixed Netty release. Regenerate Maven or Gradle metadata, rebuild deployed artifacts, and verify the runtime dependency tree no longer includes the affected coordinate. Keep edge proxy and load-balancer request-framing validation strict while rollout completes.
