Inconsistent interpretation of HTTP requests in Netty - CVE-2026-33870

 

Inconsistent interpretation of HTTP requests in Netty - CVE-2026-33870

Published: March 25, 2026


Vulnerability identifier: #VU124422
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-33870
CWE-ID: CWE-444
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to perform HTTP request smuggling attacks.

The vulnerability exists due to improper validation of HTTP requests within chunked transfer encoding extension values. A remote attacker can send a specially crafted HTTP request to the server and smuggle arbitrary HTTP headers.


Affected software

Netty
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Package Hub 15
Development Tools Module
openSUSE Leap
IBM App Connect for Manufacturing
IBM SPSS Analytic Server
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Decision Optimization for Cloud Pak for Data
IBM Sterling Partner Engagement Manager
UCD - IBM UrbanCode Deploy
Confluence Data Center
Bitbucket Data Center
Jira Software Data Center
Bamboo Data Center
Jira Service Management Data Center
IBM Automation Decision Services
Red Hat Integration Camel Extensions for Quarkus
DataStage on Cloud Pak for Data
DevOps Deploy
Rational Performance Tester
DevOps Test Performance
Storage Protect Server
IBM DB2
Oracle Database Server
Oracle Communications Cloud Native Core Policy
netty-tcnative-javadoc
netty-tcnative-debugsource
netty-tcnative
netty
netty-javadoc
Red Hat Camel for Spring Boot
JBoss Data Grid

How to mitigate CVE-2026-33870

Install updates from vendor's website.

Netty - addressed in versions 4.1.132, 4.2.11
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.2
IBM Decision Optimization for Cloud Pak for Data - update to 5.3.1 patch 4
DataStage on Cloud Pak for Data - update to 5.4
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.6, 6.2.4.4
UCD - IBM UrbanCode Deploy - addressed in versions 7.2.3.24, 7.3.2.19
DevOps Deploy - addressed in versions 8.0.1.14, 8.1.2.7, 8.2.2.0
Confluence Data Center - addressed in versions 9.2.19, 10.2.10
Bitbucket Data Center - addressed in versions 9.4.22, 10.2.4, 10.3.1
Jira Software Data Center - addressed in versions 9.12.28, 10.3.22, 11.3.5
Bamboo Data Center - addressed in versions 10.2.18, 12.1.6
Jira Service Management Data Center - addressed in versions 10.3.22, 11.3.5
DevOps Test Performance - update to 11.0.8
Oracle Database Server - update to 19.4
IBM Automation Decision Services - addressed in versions 24.0.0.0.9, 24.0.1.0.8, 25.0.0.0.4
Red Hat Integration Camel Extensions for Quarkus - update to p
netty-tcnative-javadoc - update to 2.0.75-150200.3.36.1
netty-tcnative-debugsource - update to 2.0.75-150200.3.36.1
netty-tcnative - update to 2.0.75-150200.3.36.1
netty - update to 4.1.132-150200.4.43.1
netty-javadoc - update to 4.1.132-150200.4.43.1
Red Hat Camel for Spring Boot - update to 4.14
Storage Protect Server - update to 8.2.2
JBoss Data Grid - update to 8.6.1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins