GHSA-4mp9-239f-g9hg
Dashboard / Vulnerabilities / GHSA-4mp9-239f-g9hg
Summary: Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation
Details: ## Summary An attacker can force WebSocket upgrade via the lax V07 (or V08) handshaker by sending `Sec-WebSocket-Version: 7` and omitting `Connection: Upgrade` / `Upgrade: websocket` headers, completing a protocol switch that a proxy would not recognize as an Upgrade request and enabling HTTP request smuggling / protocol-confusion attacks.
References: https://github.com/netty/netty/security/advisories/GHSA-4mp9-239f-g9hg, https://github.com/netty/netty, https://github.com/netty/netty/releases/tag/netty-4.1.136.Final, https://github.com/netty/netty/releases/tag/netty-4.2.16.Final
Affected packages
Package
Name: io.netty:netty-codec-http
Purl: pkg:maven/io.netty/netty-codec-http
Affected ranges
Type: ECOSYSTEM
Events:
