CVE-2026-89044
Last modified
CVE-2026-89044 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Netty versions 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final fail to properly validate the final transfer coding in the Transfer-Encoding header, allowing attackers to smuggle requests by using malformed encoding declarations. Attackers can split Transfer-Encoding headers across multiple lines or use values like 'chunked, xchunked' to bypass validation and decode messages as chunked when the final coding is not chunked, enabling request smuggling attacks.. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
Netty versions 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final fail to properly validate the final transfer coding in the Transfer-Encoding header, allowing attackers to smuggle requests by using malformed encoding declarations. Attackers can split Transfer-Encoding headers across multiple lines or use values like 'chunked, xchunked' to bypass validation and decode messages as chunked when the final coding is not chunked, enabling request smuggling attacks.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Netty | Netty | >= 4.1.133, < 4.1.138 |
| Netty | Netty | >= 4.2.13, < 4.2.18 |
References
- https://github.com/netty/netty/security/advisories/GHSA-hcvj-94mj-jp5cExploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-89044?
How severe is CVE-2026-89044?
How do I fix CVE-2026-89044?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-89036Appwrite before 2.0.0 contains an argument injection vulnera…8.8
- CVE-2026-89038Verizon Cloud for Android (com.vcast.mediamanager) before 26…6.2
- CVE-2026-8904The FastPicker, an order picker and order management system …4.3
- CVE-2026-89040Tencent Mass Service Engine in Cluster (MSEC) allows a remot…9.8
- CVE-2026-89042passport-saml-encrypted through 0.1.13 makes SAML signature …9.1
- CVE-2026-89043passport-saml-encrypted through 0.1.13 contains an XML signa…7.4
- CVE-2026-89045zstd-jni versions 1.4.8-4 through 1.5.7-13 fail to validate …4
- CVE-2026-89046zstd-jni versions 1.5.5-6 through 1.5.7-13 contain an out-of…8.2
- CVE-2026-89049A server-side request forgery issue due to improper validati…9.9
- CVE-2026-8905The Osiris Signature Banner plugin for WordPress is vulnerab…6.1
- CVE-2026-89050The Quads Ads Manager for Google AdSense WordPress plugin be…4.3
- CVE-2026-89054A missing authorization vulnerability in OpenNMS Horizon all…8.2
Are you affected by CVE-2026-89044?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
