Inconsistent interpretation of HTTP requests in Netty - CVE-2019-16869
Published: November 18, 2019 / Updated: February 11, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform HTTP request smuggling attack.
The vulnerability exists due to improper input validation when processing a whitespace before the colon in HTTP headers (e.g. "Transfer-Encoding : chunked"). A remote attacker can send a specially crafted HTTP request and perform HTTP request smuggling attack.
Affected software
IBM Observability with Instana
IBM PureData System for Operational Analytics
Log Analysis
IBM Cloud Transformation Advisor
Autodesk Infraworks
IBM Watson Knowledge Catalog in Cloud Pak for Data
HPE Telco IP Mediation E-Media
IBM Spectrum Protect Plus
Debian Linux
Ubuntu
openEuler
Planning Analytics Local
Security QRadar EDR
Dell Support Assist Enterprise
Dell EMC PowerStore Family Operating System
IBM Sterling Order Management
AMQ Broker
Fuse
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
RSA Authentication Manager
Red Hat Openshift Application Runtimes
Cloud Pak for Security (CP4S)
watsonx.data
libnetty-3.9-java (Ubuntu package)
netty3
netty (Debian package)
libnetty-java (Ubuntu package)
Red Hat Single Sign-On
How to mitigate CVE-2019-16869
Log Analysis - update to 1.3.8
Planning Analytics Local - update to 2.0.1
IBM Cloud Transformation Advisor - update to 3.2.1
Security QRadar EDR - update to 3.12.15
Dell Support Assist Enterprise - update to 4.00.06.00
AMQ Broker - addressed in versions 7.4.3, 7.6
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.8.0
Fuse - update to 7.5.0
Autodesk Infraworks - addressed in versions 2021.2 Hotfix 9, 2023.1 Hotfix 1
Dell EMC PowerStore Family Operating System - update to 1.0.4.0.5.003
Cloud Pak for Security (CP4S) - update to 1.10.12.0
watsonx.data - addressed in versions 2.0.2, 2.0.3
libnetty-3.9-java (Ubuntu package) - addressed in versions 3.9.0.Final-1ubuntu0.1, 3.9.9.Final-1+deb9u1build0.18.04.1
netty3 - update to 3.10.6-8
netty (Debian package) - addressed in versions 1:4.1.7-2+deb9u1, 1:4.1.33-1+deb10u1
libnetty-java (Ubuntu package) - update to 1:4.1.7-4ubuntu0.1
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 4.8.0
Red Hat Single Sign-On - update to 7.3.6
RSA Authentication Manager - update to 8.4 Patch 11
HPE Telco IP Mediation E-Media - update to 8.5.1
IBM Sterling Order Management - update to 10.0.0.29
IBM Spectrum Protect Plus - update to 10.1.6.4
External References
- https://access.redhat.com/errata/RHSA-2019:3892
- https://github.com/netty/netty/compare/netty-4.1.41.Final...netty-4.1.42.Final
- https://github.com/netty/netty/issues/9571
- https://lists.apache.org/thread.html/2494a2ac7f66af6e4646a4937b17972a4ec7cd3c7333c66ffd6c639d@%3Cdev.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/2e1cf538b502713c2c42ffa46d81f4688edb5676eb55bd9fc4b4fed7@%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/37ed432b8eb35d8bd757f53783ec3e334bd51f514534432bea7f1c3d@%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/380f6d2730603a2cd6b0a8bea9bcb21a86c199147e77e448c5f7390b@%3Ccommits.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/3e6d7aae1cca10257e3caf2d69b22f74c875f12a1314155af422569d@%3Cdev.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E
- https://lists.apache.org/thread.html/6e1e34c0d5635a987d595df9e532edac212307243bb1b49eead6d55b@%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/76540c8b0ed761bfa6c81fa28c13057f13a5448aed079d656f6a3c79@%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/9128111213b7b734ffc85db08d8f789b00a85a7f241b708e55debbd0@%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe@%3Ccommits.druid.apache.org%3E
- https://lists.apache.org/thread.html/a0f77c73af32cbe4ff0968bfcbbe80ae6361f3dccdd46f3177547266@%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E
- https://lists.apache.org/thread.html/b2cd51795f938632c6f60a4c59d9e587fbacd7f7d0e0a3684850a30f@%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/bdf7a5e597346a75d2d884ca48c767525e35137ad59d8f10b8fc943c@%3Cdev.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/cbf6e6a04cb37e9320ad20e437df63beeab1755fc0761918ed5c5a6e@%3Ccommits.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/cf5aa087632ead838f8ac3a42e9837684e7afe6e0fcb7704e0c73bc0@%3Ccommits.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/d14f721e0099b914daebe29bca199fde85d8354253be9d6d3d46507a@%3Ccommits.cassandra.apache.org%3E
- https://lists.apache.org/thread.html/d3eb0dbea75ef5c400bd49dfa1901ad50be606cca3cb29e0d01b6a54@%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/e192fe8797c192679759ffa6b15e4d0806546945a41d8ebfbc6ee3ac@%3Ccommits.tinkerpop.apache.org%3E
- https://lists.apache.org/thread.html/e39931d7cdd17241e69a0a09a89d99d7435bcc59afee8a9628d67769@%3Cdev.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/f6c5ebfb018787c764f000362d59e4b231c0a36b6253aa866de8c64e@%3Ccommits.cassandra.apache.org%3E
- https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2019/09/msg00035.html
Related Security Bulletins
- HTTP request smuggling in Netty
- Vert.x 3.8.3 update for Red Hat OpenShift Application Runtimes
- Multiple vulnerabilities in Red Hat Fuse
- Multiple vulnerabilities in Red Hat AMQ Broker
- Multiple vulnerabilities in Red Hat Process Automation Manager
- Multiple vulnerabilities in IBM PureData System for Operational Analytics
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Debian update for netty
- Multiple vulnerabilities in IBM Planning Analytics Local
- Multiple vulnerabilities in Dell EMC PowerStore Family Operating System
- Multiple vulnerabilities in IBM Sterling Order Management
- Multiple vulnerabilities in Autodesk InfraWorks
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in IBM Observability with Instana (OnPrem)
- Multiple vulnerabilities in IBM Operations Analytics - Log Analysis
- Multiple vulnerabilities in IBM Watson Knowledge Catalog on-prem
- Multiple vulnerabilities in Dell Support Assist Enterprise
- openEuler 20.03 LTS SP4 update for netty3
- openEuler 22.03 LTS SP1 update for netty3
- openEuler 24.03 LTS update for netty3
- openEuler 22.03 LTS SP4 update for netty3
- Multiple vulnerabilities in IBM watsonx.data
- openEuler 22.03 LTS SP3 update for netty3
- IBM watsonx.data update for FasterXML jackson-databind
- Multiple vulnerabilities in IBM Spectrum Protect Plus
- Multiple vulnerabilities in IBM Security QRadar EDR
- Multiple vulnerabilities in HPE Telco IP Mediation Application
- Ubuntu update for netty-3.9
- Ubuntu update for netty-3.9
- Ubuntu update for netty
- Multiple vulnerabilities in Red Hat Single Sign-On 7.3
- Multiple vulnerabilities in AMQ Broker 7.4
- RSA Authentication Manager update for third-party components