CVE-2026-42580 MEDIUM

CVE-2026-42580: Netty: HTTP Request Smuggling due to incorrect chunk size parsing

Vendor Netty
Product netty
Weakness CWE-444
Published May 13, 2026
Last update May 14, 2026

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

What the vulnerability does

01Description

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.

Key dates

02Disclosure timeline

May 13, 2026 CVE published
May 14, 2026 Record updated