SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-59898

HIGH · CVSS 7.5 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

Netty versions prior to 4.1.136.Final and 4.2.16.Final are vulnerable to a protocol confusion attack that allows an attacker to exploit the WebSocket upgrade process by manipulating handshake headers. This can lead to HTTP request smuggling, potentially compromising the integrity of web applications and their data. Organizations using affected versions of Netty should prioritize upgrading to the patched versions to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-59898
Severity
HIGH
CVSS
7.5
EPSS
0.25%

Original NVD Description

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ab attacker can force WebSocket upgrade via the lax V07 (or V08) handshaker by sending `Sec-WebSocket-Version: 7` and omitting `Connection: Upgrade` / `Upgrade: websocket` headers, completing a protocol switch that a proxy would not recognize as an Upgrade request and enabling HTTP request smuggling / protocol-confusion attacks. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.

Related CVEs

Other vulnerabilities affecting the same vendor(s)