CVE-2025-58056

EUVD-2025-26640
Netty is an asynchronous event-driven network application framework for development of maintainable high performance protocol servers and clients. In versions 4.1.124.Final, and 4.2.0.Alpha3 through 4.2.4.Final, Netty incorrectly accepts standalone newline characters (LF) as a chunk-size line terminator, regardless of a preceding carriage return (CR), instead of requiring CRLF per HTTP/1.1 standards. When combined with reverse proxies that parse LF differently (treating it as part of the chunk extension), attackers can craft requests that the proxy sees as one request but Netty processes as two, enabling request smuggling attacks. This is fixed in versions 4.1.125.Final and 4.2.5.Final.
HTTP Request/Response Smuggling
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 49.86%
Affected Products (NVD)
VendorProductVersion
nettynetty
𝑥
< 4.1.125
nettynetty
4.2.0 ≤
𝑥
< 4.2.5
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
netty
bookworm
1:4.1.48-7+deb12u2
fixed
bookworm (security)
1:4.1.48-7+deb12u2
fixed
bullseye
vulnerable
bullseye (security)
1:4.1.48-4+deb11u3
fixed
forky
1:4.1.48-16
fixed
sid
1:4.1.48-16
fixed
trixie
1:4.1.48-10+deb13u1
fixed
trixie (security)
1:4.1.48-10+deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
netty-3.9
bionic
needs-triage
jammy
dne
noble
dne
plucky
dne
questing
dne
resolute
dne
xenial
needs-triage
netty
bionic
Fixed 1:4.1.7-4ubuntu0.1+esm5
released
focal
Fixed 1:4.1.45-1ubuntu0.1~esm4
released
jammy
Fixed 1:4.1.48-4+deb11u2ubuntu0.1
released
noble
Fixed 1:4.1.48-9ubuntu0.1
released
plucky
Fixed 1:4.1.48-10ubuntu0.25.04.2
released
questing
Fixed 1:4.1.48-10ubuntu0.25.10.2
released
resolute
not-affected
trusty
ignored
xenial
Fixed 1:4.0.34-1ubuntu0.1~esm3
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
netty-tcnative
suse enterprise desktop 15 SP6
2.0.73-150200.3.30.1
fixed
suse enterprise desktop 15 SP7
2.0.73-150200.3.30.1
fixed
suse enterprise sap 15 SP3
2.0.73-150200.3.30.1
fixed
suse enterprise sap 15 SP4
2.0.73-150200.3.30.1
fixed
suse enterprise sap 15 SP5
2.0.73-150200.3.30.1
fixed
suse enterprise sap 15 SP6
2.0.73-150200.3.30.1
fixed
suse enterprise sap 15 SP7
2.0.73-150200.3.30.1
fixed
suse enterprise server 15 SP3
2.0.73-150200.3.30.1
fixed
suse enterprise server 15 SP4
2.0.73-150200.3.30.1
fixed
suse enterprise server 15 SP5
2.0.73-150200.3.30.1
fixed
suse enterprise server 15 SP6
2.0.73-150200.3.30.1
fixed
suse enterprise server 15 SP7
2.0.73-150200.3.30.1
fixed