UBUNTU-CVE-2026-59919

Source
https://ubuntu.com/security/CVE-2026-59919
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-59919.json
JSON Data
https://api.test.osv.dev/v1/vulns/UBUNTU-CVE-2026-59919
Upstream
Published
2026-07-29T18:16:00Z
Modified
2026-08-06T03:13:27.283367913Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Final, Netty's HAProxy encoder ( HAProxyMessageEncoder ) writes AFUNIX source and destination socket addresses into the HAProxy V1 text protocol without validating them for CRLF characters, so an attacker who controls an AFUNIX address can inject  \r\n  sequences and split the single PROXY header into multiple lines. This is possible because the V1 protocol uses CRLF as its line terminator and, unlike IPv4/IPv6 addresses whose format checks implicitly reject CRLF, AF_UNIX addresses are only validated for length (up to 108 bytes), allowing a forged second PROXY header line that spoofs the client source/destination IP to a downstream server or load balancer. The issue is fixed in versions 4.1.136.Final and 4.2.16.Final.

References

Affected packages

Ubuntu:Pro:14.04:LTS
netty

Package

Name
netty
Purl
pkg:deb/ubuntu/netty?arch=source&distro=esm-infra-legacy%2Ftrusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:3.*
1:3.2.6.Final-2
1:3.2.6.Final-2+deb8u2build0.14.04.1~esm1
1:3.2.6.Final-2+deb8u2ubuntu0.1~esm1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libnetty-java",
            "binary_version": "1:3.2.6.Final-2+deb8u2ubuntu0.1~esm1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-59919.json"
Ubuntu:Pro:16.04:LTS
netty

Package

Name
netty
Purl
pkg:deb/ubuntu/netty?arch=source&distro=esm-apps-legacy%2Fxenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:3.*
1:3.2.6.Final-2
1:4.*
1:4.0.32-1
1:4.0.33-1
1:4.0.34-1
1:4.0.34-1ubuntu0.1~esm1
1:4.0.34-1ubuntu0.1~esm2
1:4.0.34-1ubuntu0.1~esm3
1:4.0.34-1ubuntu0.1~esm4

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libnetty-java",
            "binary_version": "1:4.0.34-1ubuntu0.1~esm4"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-59919.json"
Ubuntu:Pro:18.04:LTS
netty

Package

Name
netty
Purl
pkg:deb/ubuntu/netty?arch=source&distro=esm-apps%2Fbionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:4.*
1:4.1.7-4
1:4.1.7-4ubuntu0.1~esm1
1:4.1.7-4ubuntu0.1
1:4.1.7-4ubuntu0.1+esm1
1:4.1.7-4ubuntu0.1+esm2
1:4.1.7-4ubuntu0.1+esm3
1:4.1.7-4ubuntu0.1+esm4
1:4.1.7-4ubuntu0.1+esm5
1:4.1.7-4ubuntu0.1+esm6

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libnetty-java",
            "binary_version": "1:4.1.7-4ubuntu0.1+esm6"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-59919.json"
Ubuntu:Pro:20.04:LTS
netty

Package

Name
netty
Purl
pkg:deb/ubuntu/netty?arch=source&distro=esm-apps%2Ffocal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:4.*
1:4.1.33-1
1:4.1.33-2
1:4.1.33-3
1:4.1.45-1
1:4.1.45-1ubuntu0.1~esm1
1:4.1.45-1ubuntu0.1~esm2
1:4.1.45-1ubuntu0.1~esm3
1:4.1.45-1ubuntu0.1~esm4
1:4.1.45-1ubuntu0.1~esm6

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libnetty-java",
            "binary_version": "1:4.1.45-1ubuntu0.1~esm6"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-59919.json"
Ubuntu:Pro:22.04:LTS
netty

Package

Name
netty
Purl
pkg:deb/ubuntu/netty?arch=source&distro=esm-apps%2Fjammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:4.*
1:4.1.48-4
1:4.1.48-4+deb11u1build0.22.04.1
1:4.1.48-4+deb11u2build0.22.04.1
1:4.1.48-4+deb11u2ubuntu0.1~esm1
1:4.1.48-4+deb11u2ubuntu0.1~esm2
1:4.1.48-4+deb11u2ubuntu0.1
1:4.1.48-4+deb11u2ubuntu0.1+esm1
1:4.1.48-4+deb11u2ubuntu0.1+esm3

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libnetty-java",
            "binary_version": "1:4.1.48-4+deb11u2ubuntu0.1+esm3"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-59919.json"
Ubuntu:Pro:24.04:LTS
netty

Package

Name
netty
Purl
pkg:deb/ubuntu/netty?arch=source&distro=esm-apps%2Fnoble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:4.*
1:4.1.48-7
1:4.1.48-8
1:4.1.48-9
1:4.1.48-9ubuntu0.1~esm1
1:4.1.48-9ubuntu0.1~esm2
1:4.1.48-9ubuntu0.1
1:4.1.48-9ubuntu0.1+esm1
1:4.1.48-9ubuntu0.1+esm3

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libnetty-java",
            "binary_version": "1:4.1.48-9ubuntu0.1+esm3"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-59919.json"
Ubuntu:Pro:26.04:LTS
netty

Package

Name
netty
Purl
pkg:deb/ubuntu/netty?arch=source&distro=esm-apps%2Fresolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:4.*
1:4.1.48-10
1:4.1.48-11
1:4.1.48-12
1:4.1.48-13
1:4.1.48-14
1:4.1.48-16
1:4.1.48-16ubuntu0.1~esm2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libnetty-buffer-java",
            "binary_version": "1:4.1.48-16ubuntu0.1~esm2"
        },
        {
            "binary_name": "libnetty-common-java",
            "binary_version": "1:4.1.48-16ubuntu0.1~esm2"
        },
        {
            "binary_name": "libnetty-java",
            "binary_version": "1:4.1.48-16ubuntu0.1~esm2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-59919.json"