{"id":"CVE-2020-7238","details":"Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line) and a later Content-Length header. This issue exists because of an incomplete fix for CVE-2019-16869.","aliases":["GHSA-ff2w-cq2g-wv5f"],"modified":"2026-07-18T03:31:28.646470561Z","published":"2020-01-27T17:15:12.277Z","database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.0"},{"last_affected":"8.0"},{"introduced":"9.0"},{"last_affected":"9.0"},{"introduced":"10.0"},{"last_affected":"10.0"}],"source":"CPE_STRING","vendor_product":"debian:debian_linux"},{"vendor_product":"fedoraproject:fedora","cpes":["cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"33"},{"last_affected":"33"}],"source":"CPE_STRING"},{"source":"CPE_STRING","vendor_product":"redhat:jboss_enterprise_application_platform","cpes":["cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.2:*:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.4:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"7.2"},{"last_affected":"7.2"},{"introduced":"7.3"},{"last_affected":"7.3"},{"introduced":"7.4"},{"last_affected":"7.4"}]}]},"references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/r131e572d003914843552fa45c4398b9903fb74144986e8b107c0a3a7%40%3Ccommits.cassandra.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rc8d554aad889d12b140d9fd7d2d6fc2e8716e9792f6f4e4b2cdc2d05%40%3Ccommits.cassandra.apache.org%3E"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TS6VX7OMXPDJIU5LRGUAHRK6MENAVJ46/"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2020:0497"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2020:0567"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2020:0601"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2020:0605"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2020:0606"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2020:0804"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2020:0805"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2020:0806"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2020:0811"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2020/02/msg00017.html"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2020/02/msg00018.html"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2020/09/msg00003.html"},{"type":"ADVISORY","url":"https://netty.io/news/"},{"type":"ADVISORY","url":"https://www.debian.org/security/2021/dsa-4885"},{"type":"EVIDENCE","url":"https://github.com/jdordonezn/CVE-2020-72381/issues/1"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/netty/netty","events":[{"introduced":"d066f163d7476a4a332f95d4dc62af751378f536"},{"last_affected":"d066f163d7476a4a332f95d4dc62af751378f536"}],"database_specific":{"extracted_events":[{"introduced":"4.1.43"},{"last_affected":"4.1.43"}],"source":"CPE_STRING","cpe":"cpe:2.3:a:netty:netty:4.1.43:*:*:*:*:*:*:*"}}],"versions":["4.1.43","netty-4.1.43.Final"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-7238.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}