CRLF injection in Netty - CVE-2025-67735

 

CRLF injection in Netty - CVE-2025-67735

Published: December 15, 2025 / Updated: February 3, 2026


Vulnerability identifier: #VU119966
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-67735
CWE-ID: CWE-93
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to inject arbitrary data in server response.

The vulnerability exists due to insufficient validation of attacker-supplied data in io.netty.handler.codec.http.HttpRequestEncoder. A remote attacker can pass specially crafted data to the application containing CR-LF characters and modify application behavior.


Affected software

Netty
Debian Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Package Hub 15
openSUSE Leap
Ubuntu
Event Processing
Security QRadar EDR
Enterprise Build of Quarkus
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component
DataStage on Cloud Pak for Data
DevOps Deploy
Rational Performance Tester
DevOps Test Performance
MongoDB Enterprise Advanced with IBM
watsonx.data
IBM SPSS Analytic Server
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Sterling Partner Engagement Manager
UCD - IBM UrbanCode Deploy
IBM Maximo Application Suite - Manage Component
IBM Automation Decision Services
Splunk AppDynamics Database Agent
IBM Cloud Object Storage Systems
Rational Test Automation Server
Event Streams
IBM DB2
Oracle Database Server
Oracle GoldenGate Big Data and Application Adapters
Oracle Banking Liquidity Management
netty (Ubuntu package)
netty (Debian package)
netty-javadoc
netty

How to mitigate CVE-2025-67735

Install updates from vendor's website.

Netty - addressed in versions 4.1.129, 4.2.8
Event Processing - update to 1.5.2
watsonx.data - update to 2.3.1
Security QRadar EDR - update to 3.12.24
Enterprise Build of Quarkus - update to 3.27.2
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.1
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component - update to 5.3.1
DataStage on Cloud Pak for Data - update to 5.3.1 patch 3
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.6, 6.2.4.4
UCD - IBM UrbanCode Deploy - addressed in versions 7.1.2.29, 7.2.3.22, 7.3.2.17
DevOps Deploy - addressed in versions 8.0.1.12, 8.1.2.5, 8.2.0.1
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.36, 8.7.30, 9.0.23, 9.1.11
Event Streams - update to 13.0.0
DevOps Test Performance - update to 11.0.8
IBM Automation Decision Services - addressed in versions 24.0.0.0.9, 24.0.1.0.8, 25.0.0.0.4
Splunk AppDynamics Database Agent - update to 26.1.0
IBM Cloud Object Storage Systems - addressed in versions 3.20.0.43, 3.20.0.69
netty (Ubuntu package) - addressed in versions 1:4.0.34-1ubuntu0.1~esm5, 1:4.1.7-4ubuntu0.1+esm7, 1:4.1.45-1ubuntu0.1~esm7, 1:4.1.48-4+deb11u2ubuntu0.2, 1:4.1.48-9ubuntu0.2
netty (Debian package) - addressed in versions 1:4.1.48-7+deb12u2, 1:4.1.48-10+deb13u1
netty-javadoc - update to 4.1.130-150200.4.40.1
netty - update to 4.1.130-150200.4.40.1
MongoDB Enterprise Advanced with IBM - update to 8.0.19
Rational Test Automation Server - update to 11.0.8

External References

Related Security Bulletins