FixVibe

high

HTTP Request Smuggling in Netty (CVE-2019-16869)

Netty releases affected by CVE-2019-16869 / GHSA-p979-4mfw-53vg can create HTTP request-smuggling risk in deployments where Netty parses traffic behind an intermediary. FixVibe GitHub repo scans flag affected Netty Maven and Gradle dependencies.

CVE-2019-16869GHSA-p979-4mfw-53vgCWE-444

Impact

Affected Netty HTTP codecs can mishandle ambiguous request framing when they parse malformed headers behind a proxy, load balancer, or cache [S1][S2]. In deployments where Netty receives untrusted HTTP traffic behind an intermediary, parser disagreement can lead to request desynchronization, security-control bypass, or cache poisoning.

Root Cause

CVE-2019-16869 affects Netty releases before the fixed 4.1.42.Final line and related legacy Maven coordinates [S1][S2]. The issue is tied to how affected HTTP parsing code treats malformed header whitespace, which can make Netty and an upstream intermediary disagree about where one request ends and the next begins.

FixVibe Coverage

FixVibe's GitHub repo scans flag Maven and Gradle projects that depend on Netty versions associated with CVE-2019-16869 / GHSA-p979-4mfw-53vg, with the dependency file, package coordinate and version.

Fix

Upgrade io.netty:netty-all to 4.1.42.Final or newer, or migrate legacy io.netty:netty / org.jboss.netty:netty usage to a maintained fixed Netty release. Regenerate Maven or Gradle metadata, rebuild deployed artifacts, and verify the runtime dependency tree no longer includes the affected coordinate. Keep edge proxy and load-balancer request-framing validation strict while rollout completes.