CRLF injection in Netty - CVE-2025-67735
Published: December 15, 2025 / Updated: February 3, 2026
Vulnerability details
The vulnerability allows a remote attacker to inject arbitrary data in server response.
The vulnerability exists due to insufficient validation of attacker-supplied data in io.netty.handler.codec.http.HttpRequestEncoder. A remote attacker can pass specially crafted data to the application containing CR-LF characters and modify application behavior.
Affected software
Debian Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Package Hub 15
openSUSE Leap
Ubuntu
Event Processing
Security QRadar EDR
Enterprise Build of Quarkus
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component
DataStage on Cloud Pak for Data
DevOps Deploy
Rational Performance Tester
DevOps Test Performance
MongoDB Enterprise Advanced with IBM
watsonx.data
IBM SPSS Analytic Server
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Sterling Partner Engagement Manager
UCD - IBM UrbanCode Deploy
IBM Maximo Application Suite - Manage Component
IBM Automation Decision Services
Splunk AppDynamics Database Agent
IBM Cloud Object Storage Systems
Rational Test Automation Server
Event Streams
IBM DB2
Oracle Database Server
Oracle GoldenGate Big Data and Application Adapters
Oracle Banking Liquidity Management
netty (Ubuntu package)
netty (Debian package)
netty-javadoc
netty
How to mitigate CVE-2025-67735
Event Processing - update to 1.5.2
watsonx.data - update to 2.3.1
Security QRadar EDR - update to 3.12.24
Enterprise Build of Quarkus - update to 3.27.2
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.1
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component - update to 5.3.1
DataStage on Cloud Pak for Data - update to 5.3.1 patch 3
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.6, 6.2.4.4
UCD - IBM UrbanCode Deploy - addressed in versions 7.1.2.29, 7.2.3.22, 7.3.2.17
DevOps Deploy - addressed in versions 8.0.1.12, 8.1.2.5, 8.2.0.1
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.36, 8.7.30, 9.0.23, 9.1.11
Event Streams - update to 13.0.0
DevOps Test Performance - update to 11.0.8
IBM Automation Decision Services - addressed in versions 24.0.0.0.9, 24.0.1.0.8, 25.0.0.0.4
Splunk AppDynamics Database Agent - update to 26.1.0
IBM Cloud Object Storage Systems - addressed in versions 3.20.0.43, 3.20.0.69
netty (Ubuntu package) - addressed in versions 1:4.0.34-1ubuntu0.1~esm5, 1:4.1.7-4ubuntu0.1+esm7, 1:4.1.45-1ubuntu0.1~esm7, 1:4.1.48-4+deb11u2ubuntu0.2, 1:4.1.48-9ubuntu0.2
netty (Debian package) - addressed in versions 1:4.1.48-7+deb12u2, 1:4.1.48-10+deb13u1
netty-javadoc - update to 4.1.130-150200.4.40.1
netty - update to 4.1.130-150200.4.40.1
MongoDB Enterprise Advanced with IBM - update to 8.0.19
Rational Test Automation Server - update to 11.0.8
External References
Related Security Bulletins
- CRLF injection in Netty
- SUSE update for netty
- Multiple vulnerabilities in Oracle Database Server
- IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) update for Netty
- Multiple vulnerabilities in IBM Enterprise Build of Quarkus
- Multiple vulnerabilities in IBM Security QRadar EDR
- Multiple vulnerabilities in MongoDB Enterprise Advanced with IBM
- IBM Maximo Application Suite - Manage Component update for Netty
- Debian update for netty
- Splunk AppDynamics Database Agent update for third-party components
- IBM SPSS Analytic Server update for Netty
- IBM watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component update for Netty
- IBM watsonx.data update for Netty
- IBM Db2 update for Netty
- IBM Watson Discovery Cartridge update for Netty
- IBM DevOps Test Performance update for Netty
- Multiple vulnerabilities in Oracle GoldenGate Big Data and Application Adapters
- Multiple vulnerabilities in Oracle Banking Liquidity Management
- IBM Rational Test Automation Server update for Netty
- Multiple vulnerabilities in IBM Cloud Object System
- IBM Event Processing update for Netty
- Multiple vulnerabilities in IBM DataStage on Cloud Pak for Data
- Multiple vulnerabilities in IBM Sterling Partner Engagement Manager
- Multiple vulnerabilities in IBM Event Streams
- Multiple vulnerabilities in IBM Automation Decision Services
- Ubuntu update for netty