Inconsistent interpretation of HTTP requests in Netty - CVE-2025-58056

 

Inconsistent interpretation of HTTP requests in Netty - CVE-2025-58056

Published: September 3, 2025


Vulnerability identifier: #VU114760
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-58056
CWE-ID: CWE-444
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform HTTP request smuggling attacks.

The vulnerability exists due to improper validation of HTTP/1.1 requests. A remote attacker can send a specially crafted HTTP request to the server and smuggle arbitrary HTTP headers.

Successful exploitation of vulnerability may allow an attacker to poison HTTP cache and perform phishing attacks.


Affected software

Netty
Debian Linux
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Enterprise Storage
Development Tools Module
SUSE Package Hub 15
openSUSE Leap
Ubuntu
Astronomer with IBM
Netezza Appliance
DataPower Operations Dashboard
Guardium Data Security Center (GDSC)
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component
DataStage on Cloud Pak for Data
Storage Scale
Maximo Application Suite - IoT Component
Rational Performance Tester
DevOps Test Performance
IBM Event Endpoint Management
watsonx Assistant Cartridge
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
MongoDB Enterprise Advanced with IBM
Guardium Data Protection
IBM Observability with Instana
PowerVC
IBM SPSS Analytic Server
IT Service Intelligence (ITSI)
IBM Watson Discovery for IBM Cloud Pak for Data
Jira Service Management Data Center
IBM Sterling Partner Engagement Manager
UCD - IBM UrbanCode Deploy
IBM Maximo Application Suite - Manage Component
Jira Software Data Center
IBM Business Automation Workflow
IBM Operator for Apache Flink
Red Hat build of Quarkus
Cryostat
JBoss Enterprise Application Platform
AMQ Streams
AMQ Broker
Event Streams
IBM DB2
netty-tcnative
netty-tcnative-javadoc
netty-tcnative-debugsource
eap8-wss4j (Red Hat package)
eap8-xml-security (Red Hat package)
eap8-apache-commons-lang (Red Hat package)
eap8-apache-cxf (Red Hat package)
netty (Ubuntu package)
eap8-apache-cxf-xjc-utils (Red Hat package)
netty (Debian package)
netty
netty-javadoc
eap8-netty-transport-native-epoll (Red Hat package)
eap8-netty (Red Hat package)
eap8-opensaml (Red Hat package)
eap8-jbossws-cxf (Red Hat package)
eap8-wildfly (Red Hat package)
eap8-eap-product-conf-parent (Red Hat package)
Red Hat Camel for Spring Boot
Splunk AppDynamics Analytics Agent

How to mitigate CVE-2025-58056

Install updates from vendor's website.

Netty - addressed in versions 4.1.125, 4.2.5
Astronomer with IBM - update to 1.1.0
Netezza Appliance - update to 1.0.0.1
DataPower Operations Dashboard - update to 1.0.23.3
IBM Observability with Instana - update to 1.0.308
Guardium Data Security Center (GDSC) - update to 3.8.5
IT Service Intelligence (ITSI) - update to 4.21.2
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.0
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component - update to 5.2.2
DataStage on Cloud Pak for Data - update to 5.2.2
Storage Scale - update to 5.2.3.5
Jira Service Management Data Center - addressed in versions 5.12.28, 10.3.11, 11.1.0
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.6, 6.2.4.4
UCD - IBM UrbanCode Deploy - addressed in versions 7.1.2.27, 7.2.3.20, 7.3.2.15, 8.0.1.10, 8.1.2.3
JBoss Enterprise Application Platform - addressed in versions 8.0.9, 8.1.0
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.31, 8.7.25, 9.0.18, 9.1.5
Maximo Application Suite - IoT Component - addressed in versions 8.7.27, 8.8.23, 9.0.13, 9.1.4
Jira Software Data Center - addressed in versions 9.12.28, 10.3.11, 11.1.0
Event Streams - update to 12.2.0
DevOps Test Performance - update to 11.0.7
IBM Event Endpoint Management - update to 11.7.0
IBM Business Automation Workflow - addressed in versions 24.0.0-IF008, 24.0.1-IF006, 25.0.0-IF003
IBM Operator for Apache Flink - update to 1.4.5
netty-tcnative - update to 2.0.73-150200.3.30.1
netty-tcnative-javadoc - update to 2.0.73-150200.3.30.1
netty-tcnative-debugsource - update to 2.0.73-150200.3.30.1
eap8-wss4j (Red Hat package) - addressed in versions 3.0.4-1.redhat_00002.1.el8eap, 3.0.4-1.redhat_00002.1.el9eap
eap8-xml-security (Red Hat package) - addressed in versions 3.0.5-1.redhat_00001.1.el8eap, 3.0.5-1.redhat_00001.1.el9eap
AMQ Streams - update to 3.1.0
Red Hat build of Quarkus - addressed in versions 3.15.7, 3.20.3
eap8-apache-commons-lang (Red Hat package) - addressed in versions 3.18.0-1.redhat_00002.1.el8eap, 3.18.0-1.redhat_00002.1.el9eap
eap8-apache-cxf (Red Hat package) - addressed in versions 4.0.9-4.redhat_00002.1.el8eap, 4.0.9-4.redhat_00002.1.el9eap, 4.0.9-5.redhat_00002.1.el8eap, 4.0.9-5.redhat_00002.1.el9eap
netty (Ubuntu package) - addressed in versions 1:4.0.34-1ubuntu0.1~esm3, 1:4.1.7-4ubuntu0.1+esm5, 1:4.1.45-1ubuntu0.1~esm4, 1:4.1.48-4+deb11u2ubuntu0.1~esm2, 1:4.1.48-9ubuntu0.1~esm2, 1:4.1.48-10ubuntu0.25.04.2, 1:4.1.48-10ubuntu0.25.10.2
Cryostat - update to 4.1.0
eap8-apache-cxf-xjc-utils (Red Hat package) - addressed in versions 4.1.0-1.redhat_00001.1.el8eap, 4.1.0-1.redhat_00001.1.el9eap
netty (Debian package) - addressed in versions 1:4.1.48-7+deb12u2, 1:4.1.48-10+deb13u1
netty - update to 4.1.126-150200.4.34.1
netty-javadoc - update to 4.1.126-150200.4.34.1
eap8-netty-transport-native-epoll (Red Hat package) - addressed in versions 4.1.127-1.Final_redhat_00001.1.el8eap, 4.1.127-1.Final_redhat_00001.1.el9eap
eap8-netty (Red Hat package) - addressed in versions 4.1.127-1.Final_redhat_00001.1.el8eap, 4.1.127-1.Final_redhat_00001.1.el9eap
eap8-opensaml (Red Hat package) - addressed in versions 4.3.2-2.redhat_00002.1.el8eap, 4.3.2-2.redhat_00002.1.el9eap
Red Hat Camel for Spring Boot - addressed in versions 4.10, 4.10.7
watsonx Assistant Cartridge - update to 5.3.0
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.3.0
eap8-jbossws-cxf (Red Hat package) - addressed in versions 7.3.4-1.Final_redhat_00001.1.el8eap, 7.3.4-1.Final_redhat_00001.1.el9eap
AMQ Broker - update to 7.13.2
eap8-wildfly (Red Hat package) - addressed in versions 8.0.9-8.GA_redhat_00008.1.el8eap, 8.0.9-8.GA_redhat_00008.1.el9eap, 8.1.0-55.GA_redhat_00016.1.el8eap, 8.1.0-55.GA_redhat_00016.1.el9eap
MongoDB Enterprise Advanced with IBM - update to 8.0.19
Guardium Data Protection - update to 12.0p50
Splunk AppDynamics Analytics Agent - update to 26.1.0
eap8-eap-product-conf-parent (Red Hat package) - addressed in versions 800.9.1-3.GA_redhat_00004.1.el8eap, 800.9.1-3.GA_redhat_00004.1.el9eap, 801.0.1-2.GA_redhat_00003.1.el8eap, 801.0.1-2.GA_redhat_00003.1.el9eap

External References

Related Security Bulletins