Netty versions 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final fail to properly validate the final transfer coding in the Transfer-Encoding header, allowing attackers to smuggle requests by using malformed encoding declarations. Attackers can split Transfer-Encoding headers across multiple lines or use values like 'chunked, xchunked' to bypass validation and decode messages as chunked when the final coding is not chunked, enabling request smuggling attacks.
{
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-444"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89044.json"
}{
"cpe": "cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "4.1.133"
},
{
"fixed": "4.1.138"
},
{
"introduced": "4.2.13"
},
{
"fixed": "4.2.18"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-89044.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "39568736426900089759731842884001121431",
"length": 963
},
"id": "CVE-2026-89044-194b26b6",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/netty/netty/commit/ca87393b0e9e13c493d213a268e727a6d44e1585",
"target": {
"file": "codec-http/src/test/java/io/netty/handler/codec/http/HttpContentDecoderTest.java",
"function": "testTransferCodingGZIP"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"214298186539008428149573032201265431326",
"208767497528323590853245687630656762383",
"122584292759714707492354862197707283357",
"37150899575777830019674626170853375708",
"156524344128213120605536486976850367514",
"76191803289853305428362306577720931675",
"7887993219363986715847329364426566796",
"113810475185888961843674884838827999788",
"34062832394674771638987967149228635436",
"190171353176343123439658925408166411391",
"225013097599673196789005472276588104778",
"156645128536275706020383125952266795151",
"116244189812830029873112056240010755526",
"160789162801118316968047505744883468189",
"50004257070498317342054104756207269621",
"272076325811464332073991181975904351152",
"130819597716836437584711753343025707428",
"162759581130878812433569382327087602401",
"314848267011393396325575501950248657128",
"51976167394046237057875893633953754572",
"268764800594008118497950903453743353128",
"321566425741706505109808183537576107700",
"237416175091393962548344101768953321490",
"10704711020933302129613267483746171930",
"213571385486221754173499573485237839893",
"257928764096402866748128958531812887015",
"21734985011249774889020767581763762746",
"57891855152342639383453279311220345641",
"175191600884945640986536729015741204087"
],
"threshold": 0.9
},
"id": "CVE-2026-89044-27b82cf7",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/netty/netty/commit/640d4d3324f7b811a4903d0730c8ccb35500500c",
"target": {
"file": "codec-http/src/main/java/io/netty/handler/codec/http/HttpObjectDecoder.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"214298186539008428149573032201265431326",
"208767497528323590853245687630656762383",
"122584292759714707492354862197707283357",
"37150899575777830019674626170853375708",
"156524344128213120605536486976850367514",
"76191803289853305428362306577720931675",
"7887993219363986715847329364426566796",
"113810475185888961843674884838827999788",
"34062832394674771638987967149228635436",
"190171353176343123439658925408166411391",
"225013097599673196789005472276588104778",
"156645128536275706020383125952266795151",
"116244189812830029873112056240010755526",
"160789162801118316968047505744883468189",
"50004257070498317342054104756207269621",
"272076325811464332073991181975904351152",
"130819597716836437584711753343025707428",
"162759581130878812433569382327087602401",
"314848267011393396325575501950248657128",
"51976167394046237057875893633953754572",
"268764800594008118497950903453743353128",
"321566425741706505109808183537576107700",
"237416175091393962548344101768953321490",
"10704711020933302129613267483746171930",
"213571385486221754173499573485237839893",
"257928764096402866748128958531812887015",
"246827039691065350757530478373759196484",
"230410851868219014943146555017660474192",
"174963503053368888803948358188865537325"
],
"threshold": 0.9
},
"id": "CVE-2026-89044-2f2c56ea",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/netty/netty/commit/ca87393b0e9e13c493d213a268e727a6d44e1585",
"target": {
"file": "codec-http/src/main/java/io/netty/handler/codec/http/HttpObjectDecoder.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"157429879275169423814572646039836412008",
"204390438376184709732150241740880708896",
"10827315443521006123079355947389536320",
"73824679276583708751307765467059221138",
"165881549488202872059324271256868413036",
"336013983184267104911858451778661568473",
"211530570869946555885822773945066196225",
"309427656831335561757624303540720969967",
"243225904040431297611064198874014216467",
"223069427424819754849401020524764981568",
"56443917329953758707575979849072741011"
],
"threshold": 0.9
},
"id": "CVE-2026-89044-40b6fbf4",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/netty/netty/commit/640d4d3324f7b811a4903d0730c8ccb35500500c",
"target": {
"file": "codec-http/src/test/java/io/netty/handler/codec/http/HttpRequestDecoderTest.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"11386370403329902816753629215842267411",
"42568944517476794754704807150268161769",
"226230070600942373797432027348827100226",
"254525265272535736897122464899582526111",
"132672430415958773917240731039457557857",
"27231847538070336383893417472455295768",
"223930259990409818339950631465600860924",
"200587257710161411098227214382707712243",
"123212513381597023041202109860337218095",
"264966121169132003545315139551689869373",
"86256158247477259628189681774484550351",
"339831881123043900558121970959201492422",
"265085101216900858206371784523034139899",
"18009516177781816328042927878651945109",
"300225838367242521985048490011931108135",
"191524764214377542194959667221798537757",
"215719905183917535507843301912331203889",
"209671406663369853816980159124177257221",
"184089561069832506395775899206897641941",
"225481025249805471688645970148154506318",
"34983402887444601630817207144783542899",
"318375003309178795237089582815133843715",
"62737397043925439862531808282180934658",
"70207953412990563970776719388243936987",
"183165819243918001449707048335626059438"
],
"threshold": 0.9
},
"id": "CVE-2026-89044-501d6c25",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/netty/netty/commit/ca87393b0e9e13c493d213a268e727a6d44e1585",
"target": {
"file": "codec-http/src/test/java/io/netty/handler/codec/http/HttpContentDecoderTest.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "283659003803254193869025090214959228676",
"length": 2819
},
"id": "CVE-2026-89044-59c5e721",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/netty/netty/commit/ca87393b0e9e13c493d213a268e727a6d44e1585",
"target": {
"file": "codec-http/src/main/java/io/netty/handler/codec/http/HttpObjectDecoder.java",
"function": "readHeaders"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "198103488756152887802241237669919006757",
"length": 189
},
"id": "CVE-2026-89044-62674746",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/netty/netty/commit/640d4d3324f7b811a4903d0730c8ccb35500500c",
"target": {
"file": "codec-http/src/test/java/io/netty/handler/codec/http/HttpRequestDecoderTest.java",
"function": "testChunkedNotLastInTransferEncoding"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "198103488756152887802241237669919006757",
"length": 189
},
"id": "CVE-2026-89044-77458c0e",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/netty/netty/commit/ca87393b0e9e13c493d213a268e727a6d44e1585",
"target": {
"file": "codec-http/src/test/java/io/netty/handler/codec/http/HttpRequestDecoderTest.java",
"function": "testChunkedNotLastInTransferEncoding"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "186418629061666400113863649290214753627",
"length": 2799
},
"id": "CVE-2026-89044-88dd5163",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/netty/netty/commit/640d4d3324f7b811a4903d0730c8ccb35500500c",
"target": {
"file": "codec-http/src/main/java/io/netty/handler/codec/http/HttpObjectDecoder.java",
"function": "readHeaders"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "39568736426900089759731842884001121431",
"length": 963
},
"id": "CVE-2026-89044-aab6a016",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/netty/netty/commit/640d4d3324f7b811a4903d0730c8ccb35500500c",
"target": {
"file": "codec-http/src/test/java/io/netty/handler/codec/http/HttpContentDecoderTest.java",
"function": "testTransferCodingGZIP"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"11386370403329902816753629215842267411",
"42568944517476794754704807150268161769",
"226230070600942373797432027348827100226",
"254525265272535736897122464899582526111",
"132672430415958773917240731039457557857",
"27231847538070336383893417472455295768",
"223930259990409818339950631465600860924",
"200587257710161411098227214382707712243",
"123212513381597023041202109860337218095",
"264966121169132003545315139551689869373",
"86256158247477259628189681774484550351",
"339831881123043900558121970959201492422",
"265085101216900858206371784523034139899",
"18009516177781816328042927878651945109",
"300225838367242521985048490011931108135",
"191524764214377542194959667221798537757",
"215719905183917535507843301912331203889",
"209671406663369853816980159124177257221",
"184089561069832506395775899206897641941",
"225481025249805471688645970148154506318",
"34983402887444601630817207144783542899",
"318375003309178795237089582815133843715",
"62737397043925439862531808282180934658",
"70207953412990563970776719388243936987",
"183165819243918001449707048335626059438"
],
"threshold": 0.9
},
"id": "CVE-2026-89044-b6713b4d",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/netty/netty/commit/640d4d3324f7b811a4903d0730c8ccb35500500c",
"target": {
"file": "codec-http/src/test/java/io/netty/handler/codec/http/HttpContentDecoderTest.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"157429879275169423814572646039836412008",
"204390438376184709732150241740880708896",
"10827315443521006123079355947389536320",
"73824679276583708751307765467059221138",
"165881549488202872059324271256868413036",
"336013983184267104911858451778661568473",
"211530570869946555885822773945066196225",
"309427656831335561757624303540720969967",
"243225904040431297611064198874014216467",
"223069427424819754849401020524764981568",
"56443917329953758707575979849072741011"
],
"threshold": 0.9
},
"id": "CVE-2026-89044-dacbc3c3",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/netty/netty/commit/ca87393b0e9e13c493d213a268e727a6d44e1585",
"target": {
"file": "codec-http/src/test/java/io/netty/handler/codec/http/HttpRequestDecoderTest.java"
}
}
]
"2026-09-30T08:16:58Z"