Inconsistent interpretation of HTTP requests in Netty - CVE-2025-58056
Published: September 3, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform HTTP request smuggling attacks.
The vulnerability exists due to improper validation of HTTP/1.1 requests. A remote attacker can send a specially crafted HTTP request to the server and smuggle arbitrary HTTP headers.
Successful exploitation of vulnerability may allow an attacker to poison HTTP cache and perform phishing attacks.
Affected software
Debian Linux
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Enterprise Storage
Development Tools Module
SUSE Package Hub 15
openSUSE Leap
Ubuntu
Astronomer with IBM
Netezza Appliance
DataPower Operations Dashboard
Guardium Data Security Center (GDSC)
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component
DataStage on Cloud Pak for Data
Storage Scale
Maximo Application Suite - IoT Component
Rational Performance Tester
DevOps Test Performance
IBM Event Endpoint Management
watsonx Assistant Cartridge
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
MongoDB Enterprise Advanced with IBM
Guardium Data Protection
IBM Observability with Instana
PowerVC
IBM SPSS Analytic Server
IT Service Intelligence (ITSI)
IBM Watson Discovery for IBM Cloud Pak for Data
Jira Service Management Data Center
IBM Sterling Partner Engagement Manager
UCD - IBM UrbanCode Deploy
IBM Maximo Application Suite - Manage Component
Jira Software Data Center
IBM Business Automation Workflow
IBM Operator for Apache Flink
Red Hat build of Quarkus
Cryostat
JBoss Enterprise Application Platform
AMQ Streams
AMQ Broker
Event Streams
IBM DB2
netty-tcnative
netty-tcnative-javadoc
netty-tcnative-debugsource
eap8-wss4j (Red Hat package)
eap8-xml-security (Red Hat package)
eap8-apache-commons-lang (Red Hat package)
eap8-apache-cxf (Red Hat package)
netty (Ubuntu package)
eap8-apache-cxf-xjc-utils (Red Hat package)
netty (Debian package)
netty
netty-javadoc
eap8-netty-transport-native-epoll (Red Hat package)
eap8-netty (Red Hat package)
eap8-opensaml (Red Hat package)
eap8-jbossws-cxf (Red Hat package)
eap8-wildfly (Red Hat package)
eap8-eap-product-conf-parent (Red Hat package)
Red Hat Camel for Spring Boot
Splunk AppDynamics Analytics Agent
How to mitigate CVE-2025-58056
Astronomer with IBM - update to 1.1.0
Netezza Appliance - update to 1.0.0.1
DataPower Operations Dashboard - update to 1.0.23.3
IBM Observability with Instana - update to 1.0.308
Guardium Data Security Center (GDSC) - update to 3.8.5
IT Service Intelligence (ITSI) - update to 4.21.2
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.0
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component - update to 5.2.2
DataStage on Cloud Pak for Data - update to 5.2.2
Storage Scale - update to 5.2.3.5
Jira Service Management Data Center - addressed in versions 5.12.28, 10.3.11, 11.1.0
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.6, 6.2.4.4
UCD - IBM UrbanCode Deploy - addressed in versions 7.1.2.27, 7.2.3.20, 7.3.2.15, 8.0.1.10, 8.1.2.3
JBoss Enterprise Application Platform - addressed in versions 8.0.9, 8.1.0
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.31, 8.7.25, 9.0.18, 9.1.5
Maximo Application Suite - IoT Component - addressed in versions 8.7.27, 8.8.23, 9.0.13, 9.1.4
Jira Software Data Center - addressed in versions 9.12.28, 10.3.11, 11.1.0
Event Streams - update to 12.2.0
DevOps Test Performance - update to 11.0.7
IBM Event Endpoint Management - update to 11.7.0
IBM Business Automation Workflow - addressed in versions 24.0.0-IF008, 24.0.1-IF006, 25.0.0-IF003
IBM Operator for Apache Flink - update to 1.4.5
netty-tcnative - update to 2.0.73-150200.3.30.1
netty-tcnative-javadoc - update to 2.0.73-150200.3.30.1
netty-tcnative-debugsource - update to 2.0.73-150200.3.30.1
eap8-wss4j (Red Hat package) - addressed in versions 3.0.4-1.redhat_00002.1.el8eap, 3.0.4-1.redhat_00002.1.el9eap
eap8-xml-security (Red Hat package) - addressed in versions 3.0.5-1.redhat_00001.1.el8eap, 3.0.5-1.redhat_00001.1.el9eap
AMQ Streams - update to 3.1.0
Red Hat build of Quarkus - addressed in versions 3.15.7, 3.20.3
eap8-apache-commons-lang (Red Hat package) - addressed in versions 3.18.0-1.redhat_00002.1.el8eap, 3.18.0-1.redhat_00002.1.el9eap
eap8-apache-cxf (Red Hat package) - addressed in versions 4.0.9-4.redhat_00002.1.el8eap, 4.0.9-4.redhat_00002.1.el9eap, 4.0.9-5.redhat_00002.1.el8eap, 4.0.9-5.redhat_00002.1.el9eap
netty (Ubuntu package) - addressed in versions 1:4.0.34-1ubuntu0.1~esm3, 1:4.1.7-4ubuntu0.1+esm5, 1:4.1.45-1ubuntu0.1~esm4, 1:4.1.48-4+deb11u2ubuntu0.1~esm2, 1:4.1.48-9ubuntu0.1~esm2, 1:4.1.48-10ubuntu0.25.04.2, 1:4.1.48-10ubuntu0.25.10.2
Cryostat - update to 4.1.0
eap8-apache-cxf-xjc-utils (Red Hat package) - addressed in versions 4.1.0-1.redhat_00001.1.el8eap, 4.1.0-1.redhat_00001.1.el9eap
netty (Debian package) - addressed in versions 1:4.1.48-7+deb12u2, 1:4.1.48-10+deb13u1
netty - update to 4.1.126-150200.4.34.1
netty-javadoc - update to 4.1.126-150200.4.34.1
eap8-netty-transport-native-epoll (Red Hat package) - addressed in versions 4.1.127-1.Final_redhat_00001.1.el8eap, 4.1.127-1.Final_redhat_00001.1.el9eap
eap8-netty (Red Hat package) - addressed in versions 4.1.127-1.Final_redhat_00001.1.el8eap, 4.1.127-1.Final_redhat_00001.1.el9eap
eap8-opensaml (Red Hat package) - addressed in versions 4.3.2-2.redhat_00002.1.el8eap, 4.3.2-2.redhat_00002.1.el9eap
Red Hat Camel for Spring Boot - addressed in versions 4.10, 4.10.7
watsonx Assistant Cartridge - update to 5.3.0
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.3.0
eap8-jbossws-cxf (Red Hat package) - addressed in versions 7.3.4-1.Final_redhat_00001.1.el8eap, 7.3.4-1.Final_redhat_00001.1.el9eap
AMQ Broker - update to 7.13.2
eap8-wildfly (Red Hat package) - addressed in versions 8.0.9-8.GA_redhat_00008.1.el8eap, 8.0.9-8.GA_redhat_00008.1.el9eap, 8.1.0-55.GA_redhat_00016.1.el8eap, 8.1.0-55.GA_redhat_00016.1.el9eap
MongoDB Enterprise Advanced with IBM - update to 8.0.19
Guardium Data Protection - update to 12.0p50
Splunk AppDynamics Analytics Agent - update to 26.1.0
eap8-eap-product-conf-parent (Red Hat package) - addressed in versions 800.9.1-3.GA_redhat_00004.1.el8eap, 800.9.1-3.GA_redhat_00004.1.el9eap, 801.0.1-2.GA_redhat_00003.1.el8eap, 801.0.1-2.GA_redhat_00003.1.el9eap
External References
Related Security Bulletins
- Multiple vulnerabilities in Netty
- SUSE update for netty, netty-tcnative
- Multiple vulnerabilities in AMQ Broker 7.13
- Multiple vulnerabilities in IBM DevOps Deploy / IBM UrbanCode Deploy (UCD)
- Inconsistent interpretation of HTTP requests in Red Hat Camel for Spring Boot 4
- Jira Software Data Center update for netty-codec-http
- Jira Service Management Data Center update for HTTP request smuggling in io.netty:netty-codec-http
- Multiple vulnerabilities in Red Hat Camel for Spring Boot 4.10
- Multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform
- Multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform 8.0
- Multiple vulnerabilities in Red Hat build of Quarkus 3.15
- Multiple vulnerabilities in Red Hat build of Quarkus 3.20
- IBM PowerVC update for Netty
- Multiple vulnerabilities in Red Hat build of Cryostat
- Multiple vulnerabilities in IBM Observability with Instana
- Multiple vulnerabilities in IBM Guardium Data Security Center
- Ubuntu update for netty
- IBM DataStage on Cloud Pak for Data update for Netty
- Red Hat AMQ Streams update for Apache Kafka
- IBM Netezza Appliance update for Netty
- IBM watsonx Assistant Cartridge and IBM watsonx Orchestrate with watsonx Assistant Cartridge update for Netty
- IBM Rational Performance Tester update for Netty
- Multiple vulnerabilities in IBM Event Streams
- Multiple vulnerabilities in IBM Operator for Apache Flink
- Multiple vulnerabilities in IBM Storage Scale
- Astronomer with IBM update for Netty
- IBM watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component update for Netty
- Multiple vulnerabilities in IBM Db2
- IBM Watson Discovery Cartridge update for Netty
- Multiple vulnerabilities in IBM Business Automation Workflow
- Multiple vulnerabilities in IBM Event Endpoint Management
- Multiple vulnerabilities in IBM Guardium Data Protection
- IBM Maximo Application Suite - Manage Component update for Netty
- Multiple vulnerabilities in MongoDB Enterprise Advanced with IBM
- Multiple vulnerabilities in IBM Maximo Application Suite - IoT Component
- Debian update for netty
- Splunk AppDynamics Analytics Agent update for third-party components
- Multiple vulnerabilities in IBM Datapower Operations Dashboard
- Splunk IT Service Intelligence update for third-party components
- Multiple vulnerabilities in IBM SPSS Analytic Server
- Multiple vulnerabilities in IBM Sterling Partner Engagement Manager