Inconsistent interpretation of HTTP requests in Netty - CVE-2021-21295
Published: April 1, 2021 / Updated: February 11, 2025
Vulnerability details
The vulnerability allows a remote attacker to preform HTTP request smuggling attacks.
The vulnerability exists due to improper validation of HTTP requests in io.netty:netty-codec-http2 when converting HTTP/2 to HTTP/1 streams. A remote attacker can send a specially crafted HTTP request to the server and smuggle arbitrary HTTP headers.
Successful exploitation of vulnerability may allow an attacker to poison HTTP cache and perform phishing attacks.
Affected software
IBM Observability with Instana
Log Analysis
IBM Operations Analytics Predictive Insights
IBM Cloud Transformation Advisor
AMQ Clients
IBM Watson Knowledge Catalog in Cloud Pak for Data
Autodesk Infraworks
Netcool Operations Insight
Dell Secure Connect Gateway
IBM Watson Machine Learning on CP4D
IBM Spectrum Protect Plus
qpid-proton (Red Hat package)
netty (Debian package)
libnetty-java (Ubuntu package)
netty-help
netty
AMQ Streams
AMQ Broker
Fuse
Security QRadar EDR
DataStage on Cloud Pak for Data
Dell EMC OpenManage Enterprise Services
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
IBM Sterling Order Management
BIG-IQ Centralized Management
Oracle Communications Pricing Design Center
Ubuntu
openEuler
Cloud Pak for Security (CP4S)
IBM Qradar SIEM
Red Hat Single Sign-On
IBM Security Guardium
How to mitigate CVE-2021-21295
qpid-proton (Red Hat package) - addressed in versions 0.33.0-6.el7_9, 0.33.0-8.el8
Log Analysis - update to 1.3.8
IBM Operations Analytics Predictive Insights - update to 1.3.6.8
AMQ Streams - update to 1.8.0
IBM Cloud Transformation Advisor - update to 3.2.1
Security QRadar EDR - update to 3.12.15
netty (Debian package) - update to 1:4.1.33-1+deb10u2
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.8, 4.8.9, 5.1.1, 5.1.2, 5.1.3
DataStage on Cloud Pak for Data - update to 4.8.5
AMQ Broker - addressed in versions 7.8.2, 7.9.0
Oracle Communications Pricing Design Center - update to 12.0.0.7.0
Autodesk Infraworks - addressed in versions 2021.2 Hotfix 9, 2023.1 Hotfix 1
libnetty-java (Ubuntu package) - addressed in versions Ubuntu Pro, 1:4.1.48-4+deb11u1build0.22.04.1, 1:4.1.48-5ubuntu0.1
Dell EMC OpenManage Enterprise Services - update to 1.2
Netcool Operations Insight - update to 1.6.6
Cloud Pak for Security (CP4S) - update to 1.10.12.0
netty-help - update to 4.1.13-11
netty - update to 4.1.13-11
DB2 on Cloud Pak for Data - update to 4.8.5
DB2 Warehouse on Cloud Pak for Data - update to 4.8.5
Dell Secure Connect Gateway - update to 5.0
IBM Watson Machine Learning on CP4D - update to 5.3.0
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 9, 7.5.0 Update Pack 5
Red Hat Single Sign-On - update to 7.4.7
Fuse - update to 7.10.0
IBM Sterling Order Management - update to 10.0.0.29
IBM Spectrum Protect Plus - update to 10.1.6.4
IBM Security Guardium - addressed in versions 11.0p360, 11.0p430
External References
- https://github.com/Netflix/zuul/pull/980
- https://github.com/netty/netty/commit/89c241e3b1795ff257af4ad6eadc616cb2fb3dc4
- https://github.com/netty/netty/security/advisories/GHSA-wm47-8v5p-wjpj
- https://lists.apache.org/thread.html/r02e467123d45006a1dda20a38349e9c74c3a4b53e2e07be0939ecb3f@%3Cdev.ranger.apache.org%3E
- https://lists.apache.org/thread.html/r1908a34b9cc7120e5c19968a116ddbcffea5e9deb76c2be4fa461904@%3Cdev.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r1bca0b81193b74a451fc6d687ab58ef3a1f5ec40f6c61561d8dd9509@%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r22adb45fe902aeafcd0a1c4db13984224a667676c323c66db3af38a1@%3Ccommits.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r312ce5bd3c6bf08c138349b507b6f1c25fe9cf40b6f2b0014c9d12b1@%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r3c293431c781696681abbfe1c573c2d9dcdae6fd3ff330ea22f0433f@%3Cjira.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r3ff9e735ca33612d900607dc139ebd38a64cadc6bce292e53eb86d7f@%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r490ca5611c150d193b320a2608209180713b7c68e501b67b0cffb925@%3Ccommits.servicecomb.apache.org%3E
- https://lists.apache.org/thread.html/r5232e33a1f3b310a3e083423f736f3925ebdb150844d60ac582809f8@%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r5470456cf1409a99893ae9dd57439799f6dc1a60fda90e11570f66fe@%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r57245853c7245baab09eae08728c52b58fd77666538092389cc3e882@%3Ccommits.servicecomb.apache.org%3E
- https://lists.apache.org/thread.html/r59bac5c09f7a4179b9e2460e8f41c278aaf3b9a21cc23678eb893e41@%3Cjira.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r5e66e286afb5506cdfe9bbf68a323e8d09614f6d1ddc806ed0224700@%3Cjira.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r67e6a636cbc1958383a1cd72b7fd0cd7493360b1dd0e6c12f5761798@%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r6a122c25e352eb134d01e7f4fc4d345a491c5ee9453fef6fc754d15b@%3Ccommits.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r6a29316d758db628a1df49ca219d64caf493999b52cc77847bfba675@%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r6d32fc3cd547f7c9a288a57c7f525f5d00a00d5d163613e0d10a23ef@%3Ccommits.servicecomb.apache.org%3E
- https://lists.apache.org/thread.html/r70cebada51bc6d49138272437d8a28fe971d0197334ef906b575044c@%3Ccommits.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r790c2926efcd062067eb18fde2486527596d7275381cfaff2f7b3890@%3Cissues.bookkeeper.apache.org%3E
- https://lists.apache.org/thread.html/r7bb3cdc192e9a6f863d3ea05422f09fa1ae2b88d4663e63696ee7ef5@%3Cdev.ranger.apache.org%3E
- https://lists.apache.org/thread.html/r837bbcbf12e335e83ab448b1bd2c1ad7e86efdc14034b23811422e6a@%3Ccommits.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r8db1d7b3b9acc9e8d2776395e280eb9615dd7790e1da8c57039963de@%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r9051e4f484a970b5566dc1870ecd9c1eb435214e2652cf3ea4d0c0cc@%3Cjira.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r9924ef9357537722b28d04c98a189750b80694a19754e5057c34ca48@%3Ccommits.pulsar.apache.org%3E
- https://lists.apache.org/thread.html/rb06c1e766aa45ee422e8261a8249b561784186483e8f742ea627bda4@%3Cdev.kafka.apache.org%3E
- https://lists.apache.org/thread.html/rb51d6202ff1a773f96eaa694b7da4ad3f44922c40b3d4e1a19c2f325@%3Ccommits.pulsar.apache.org%3E
- https://lists.apache.org/thread.html/rb523bb6c60196c5f58514b86a8585c2069a4852039b45de3818b29d2@%3Ccommits.servicecomb.apache.org%3E
- https://lists.apache.org/thread.html/rb592033a2462548d061a83ac9449c5ff66098751748fcd1e2d008233@%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/rbadcbcb50195f00bbd196403865ced521ca70787999583c07be38d0e@%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/rbed09768f496244a2e138dbbe6d2847ddf796c9c8ef9e50f2e3e30d9@%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/rc0087125cb15b4b78e44000f841cd37fefedfda942fd7ddf3ad1b528@%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/rcd163e421273e8dca1c71ea298dce3dd11b41d51c3a812e0394e6a5d@%3Ccommits.pulsar.apache.org%3E
- https://lists.apache.org/thread.html/rcfc535afd413d9934d6ee509dce234dac41fa3747a7555befb17447e@%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/rdb4db3f5a9c478ca52a7b164680b88877a5a9c174e7047676c006b2c@%3Ccommits.servicecomb.apache.org%3E
- https://lists.apache.org/thread.html/re6207ebe2ca4d44f2a6deee695ad6f27fd29d78980f1d46ed1574f91@%3Cissues.zookeeper.apache.org%3E
Related Security Bulletins
- HTTP request smuggling in Netty
- Debian update for netty
- Red Hat AMQ Clients 2.9.1 update for netty
- Multiple vulnerabilities in Red Hat AMQ Broker
- Multiple vulnerabilities in Red Hat AMQ Streams
- Multiple vulnerabilities in Red Hat AMQ Broker
- HTTP request smuggling within the Netty component in BIG-IQ Centralized Management
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in Dell EMC SupportAssist Enterprise
- Multiple vulnerabilities in Oracle Communications Pricing Design Center
- Multiple vulnerabilities in IBM Sterling Order Management
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in Autodesk InfraWorks
- Ubuntu update for netty
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM Observability with Instana (OnPrem)
- openEuler 20.03 LTS SP1 update for netty
- Multiple vulnerabilities in IBM Operations Analytics - Log Analysis
- Multiple vulnerabilities in IBM Operations Analytics Predictive Insights
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data
- Multiple vulnerabilities in Red Hat Single Sign-On 7.4
- Multiple vulnerabilities in Fuse 7.10
- Multiple vulnerabilities in IBM Spectrum Protect Plus
- Multiple vulnerabilities in IBM Security Guardium
- Multiple vulnerabilities in IBM Security QRadar EDR
- Multiple vulnerabilities in IBM DataStage on Cloud Pak for Data
- Multiple vulnerabilities in IBM Watson Knowledge Catalog
- Multiple vulnerabilities in IBM Watson Machine Learning