CVE-2026-89044

Source
https://cve.org/CVERecord?id=CVE-2026-89044
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-89044.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-89044
Aliases
  • GHSA-hcvj-94mj-jp5c
Downstream
CGA (2)
CLEANSTART (2)
DEBIAN (1)
openSUSE (1)
SUSE (1)
UBUNTU (1)
Related
Published
2026-09-10T17:39:34Z
Modified
2026-09-30T12:11:39Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Netty 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final HTTP Request Smuggling via Transfer-Encoding
Details

Netty versions 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final fail to properly validate the final transfer coding in the Transfer-Encoding header, allowing attackers to smuggle requests by using malformed encoding declarations. Attackers can split Transfer-Encoding headers across multiple lines or use values like 'chunked, xchunked' to bypass validation and decode messages as chunked when the final coding is not chunked, enabling request smuggling attacks.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-444"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89044.json"
}
References

Affected packages

Git / github.com/netty/netty

Affected ranges

Type
GIT
Repo
https://github.com/netty/netty
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "4.1.133"
        },
        {
            "fixed": "4.1.138"
        },
        {
            "introduced": "4.2.13"
        },
        {
            "fixed": "4.2.18"
        }
    ],
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

netty-4.*
netty-4.1.133.Final
netty-4.1.134.Final
netty-4.1.135.Final
netty-4.1.136.Final
netty-4.1.137.Final
netty-4.2.13.Final
netty-4.2.14.Final
netty-4.2.15.Final
netty-4.2.16.Final
netty-4.2.17.Final
Other
netty-clang-bin

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-89044.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "function_hash": "39568736426900089759731842884001121431",
            "length": 963
        },
        "id": "CVE-2026-89044-194b26b6",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/netty/netty/commit/ca87393b0e9e13c493d213a268e727a6d44e1585",
        "target": {
            "file": "codec-http/src/test/java/io/netty/handler/codec/http/HttpContentDecoderTest.java",
            "function": "testTransferCodingGZIP"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "214298186539008428149573032201265431326",
                "208767497528323590853245687630656762383",
                "122584292759714707492354862197707283357",
                "37150899575777830019674626170853375708",
                "156524344128213120605536486976850367514",
                "76191803289853305428362306577720931675",
                "7887993219363986715847329364426566796",
                "113810475185888961843674884838827999788",
                "34062832394674771638987967149228635436",
                "190171353176343123439658925408166411391",
                "225013097599673196789005472276588104778",
                "156645128536275706020383125952266795151",
                "116244189812830029873112056240010755526",
                "160789162801118316968047505744883468189",
                "50004257070498317342054104756207269621",
                "272076325811464332073991181975904351152",
                "130819597716836437584711753343025707428",
                "162759581130878812433569382327087602401",
                "314848267011393396325575501950248657128",
                "51976167394046237057875893633953754572",
                "268764800594008118497950903453743353128",
                "321566425741706505109808183537576107700",
                "237416175091393962548344101768953321490",
                "10704711020933302129613267483746171930",
                "213571385486221754173499573485237839893",
                "257928764096402866748128958531812887015",
                "21734985011249774889020767581763762746",
                "57891855152342639383453279311220345641",
                "175191600884945640986536729015741204087"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-89044-27b82cf7",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/netty/netty/commit/640d4d3324f7b811a4903d0730c8ccb35500500c",
        "target": {
            "file": "codec-http/src/main/java/io/netty/handler/codec/http/HttpObjectDecoder.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "214298186539008428149573032201265431326",
                "208767497528323590853245687630656762383",
                "122584292759714707492354862197707283357",
                "37150899575777830019674626170853375708",
                "156524344128213120605536486976850367514",
                "76191803289853305428362306577720931675",
                "7887993219363986715847329364426566796",
                "113810475185888961843674884838827999788",
                "34062832394674771638987967149228635436",
                "190171353176343123439658925408166411391",
                "225013097599673196789005472276588104778",
                "156645128536275706020383125952266795151",
                "116244189812830029873112056240010755526",
                "160789162801118316968047505744883468189",
                "50004257070498317342054104756207269621",
                "272076325811464332073991181975904351152",
                "130819597716836437584711753343025707428",
                "162759581130878812433569382327087602401",
                "314848267011393396325575501950248657128",
                "51976167394046237057875893633953754572",
                "268764800594008118497950903453743353128",
                "321566425741706505109808183537576107700",
                "237416175091393962548344101768953321490",
                "10704711020933302129613267483746171930",
                "213571385486221754173499573485237839893",
                "257928764096402866748128958531812887015",
                "246827039691065350757530478373759196484",
                "230410851868219014943146555017660474192",
                "174963503053368888803948358188865537325"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-89044-2f2c56ea",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/netty/netty/commit/ca87393b0e9e13c493d213a268e727a6d44e1585",
        "target": {
            "file": "codec-http/src/main/java/io/netty/handler/codec/http/HttpObjectDecoder.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "157429879275169423814572646039836412008",
                "204390438376184709732150241740880708896",
                "10827315443521006123079355947389536320",
                "73824679276583708751307765467059221138",
                "165881549488202872059324271256868413036",
                "336013983184267104911858451778661568473",
                "211530570869946555885822773945066196225",
                "309427656831335561757624303540720969967",
                "243225904040431297611064198874014216467",
                "223069427424819754849401020524764981568",
                "56443917329953758707575979849072741011"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-89044-40b6fbf4",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/netty/netty/commit/640d4d3324f7b811a4903d0730c8ccb35500500c",
        "target": {
            "file": "codec-http/src/test/java/io/netty/handler/codec/http/HttpRequestDecoderTest.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "11386370403329902816753629215842267411",
                "42568944517476794754704807150268161769",
                "226230070600942373797432027348827100226",
                "254525265272535736897122464899582526111",
                "132672430415958773917240731039457557857",
                "27231847538070336383893417472455295768",
                "223930259990409818339950631465600860924",
                "200587257710161411098227214382707712243",
                "123212513381597023041202109860337218095",
                "264966121169132003545315139551689869373",
                "86256158247477259628189681774484550351",
                "339831881123043900558121970959201492422",
                "265085101216900858206371784523034139899",
                "18009516177781816328042927878651945109",
                "300225838367242521985048490011931108135",
                "191524764214377542194959667221798537757",
                "215719905183917535507843301912331203889",
                "209671406663369853816980159124177257221",
                "184089561069832506395775899206897641941",
                "225481025249805471688645970148154506318",
                "34983402887444601630817207144783542899",
                "318375003309178795237089582815133843715",
                "62737397043925439862531808282180934658",
                "70207953412990563970776719388243936987",
                "183165819243918001449707048335626059438"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-89044-501d6c25",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/netty/netty/commit/ca87393b0e9e13c493d213a268e727a6d44e1585",
        "target": {
            "file": "codec-http/src/test/java/io/netty/handler/codec/http/HttpContentDecoderTest.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "283659003803254193869025090214959228676",
            "length": 2819
        },
        "id": "CVE-2026-89044-59c5e721",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/netty/netty/commit/ca87393b0e9e13c493d213a268e727a6d44e1585",
        "target": {
            "file": "codec-http/src/main/java/io/netty/handler/codec/http/HttpObjectDecoder.java",
            "function": "readHeaders"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "198103488756152887802241237669919006757",
            "length": 189
        },
        "id": "CVE-2026-89044-62674746",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/netty/netty/commit/640d4d3324f7b811a4903d0730c8ccb35500500c",
        "target": {
            "file": "codec-http/src/test/java/io/netty/handler/codec/http/HttpRequestDecoderTest.java",
            "function": "testChunkedNotLastInTransferEncoding"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "198103488756152887802241237669919006757",
            "length": 189
        },
        "id": "CVE-2026-89044-77458c0e",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/netty/netty/commit/ca87393b0e9e13c493d213a268e727a6d44e1585",
        "target": {
            "file": "codec-http/src/test/java/io/netty/handler/codec/http/HttpRequestDecoderTest.java",
            "function": "testChunkedNotLastInTransferEncoding"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "186418629061666400113863649290214753627",
            "length": 2799
        },
        "id": "CVE-2026-89044-88dd5163",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/netty/netty/commit/640d4d3324f7b811a4903d0730c8ccb35500500c",
        "target": {
            "file": "codec-http/src/main/java/io/netty/handler/codec/http/HttpObjectDecoder.java",
            "function": "readHeaders"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "39568736426900089759731842884001121431",
            "length": 963
        },
        "id": "CVE-2026-89044-aab6a016",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/netty/netty/commit/640d4d3324f7b811a4903d0730c8ccb35500500c",
        "target": {
            "file": "codec-http/src/test/java/io/netty/handler/codec/http/HttpContentDecoderTest.java",
            "function": "testTransferCodingGZIP"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "11386370403329902816753629215842267411",
                "42568944517476794754704807150268161769",
                "226230070600942373797432027348827100226",
                "254525265272535736897122464899582526111",
                "132672430415958773917240731039457557857",
                "27231847538070336383893417472455295768",
                "223930259990409818339950631465600860924",
                "200587257710161411098227214382707712243",
                "123212513381597023041202109860337218095",
                "264966121169132003545315139551689869373",
                "86256158247477259628189681774484550351",
                "339831881123043900558121970959201492422",
                "265085101216900858206371784523034139899",
                "18009516177781816328042927878651945109",
                "300225838367242521985048490011931108135",
                "191524764214377542194959667221798537757",
                "215719905183917535507843301912331203889",
                "209671406663369853816980159124177257221",
                "184089561069832506395775899206897641941",
                "225481025249805471688645970148154506318",
                "34983402887444601630817207144783542899",
                "318375003309178795237089582815133843715",
                "62737397043925439862531808282180934658",
                "70207953412990563970776719388243936987",
                "183165819243918001449707048335626059438"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-89044-b6713b4d",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/netty/netty/commit/640d4d3324f7b811a4903d0730c8ccb35500500c",
        "target": {
            "file": "codec-http/src/test/java/io/netty/handler/codec/http/HttpContentDecoderTest.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "157429879275169423814572646039836412008",
                "204390438376184709732150241740880708896",
                "10827315443521006123079355947389536320",
                "73824679276583708751307765467059221138",
                "165881549488202872059324271256868413036",
                "336013983184267104911858451778661568473",
                "211530570869946555885822773945066196225",
                "309427656831335561757624303540720969967",
                "243225904040431297611064198874014216467",
                "223069427424819754849401020524764981568",
                "56443917329953758707575979849072741011"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-89044-dacbc3c3",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/netty/netty/commit/ca87393b0e9e13c493d213a268e727a6d44e1585",
        "target": {
            "file": "codec-http/src/test/java/io/netty/handler/codec/http/HttpRequestDecoderTest.java"
        }
    }
]
vanir_signatures_modified
"2026-09-30T08:16:58Z"