CVE-2025-67735

EUVD-2025-203450
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.
CRLF Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 22.8%
Affected Products (NVD)
VendorProductVersion
nettynetty
𝑥
< 4.1.129
nettynetty
4.2.0 ≤
𝑥
< 4.2.8
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
netty
bookworm
1:4.1.48-7+deb12u2
fixed
bookworm (security)
1:4.1.48-7+deb12u2
fixed
forky
1:4.1.48-16
fixed
sid
1:4.1.48-16
fixed
trixie
1:4.1.48-10+deb13u1
fixed
trixie (security)
1:4.1.48-10+deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
netty
bionic
Fixed 1:4.1.7-4ubuntu0.1+esm7
released
focal
Fixed 1:4.1.45-1ubuntu0.1~esm7
released
jammy
Fixed 1:4.1.48-4+deb11u2ubuntu0.2
released
noble
Fixed 1:4.1.48-9ubuntu0.2
released
plucky
ignored
questing
ignored
resolute
not-affected
trusty
ignored
xenial
Fixed 1:4.0.34-1ubuntu0.1~esm5
released