Alerts This Week
Warning Icon 1 1,308
Alerts This Week
Warning Icon 1 1,308

SUSE Netty Important HTTP Smuggling Vulnern 2026-2308-1

suse
Calendar Grey June 9, 2026
Dist Suse Esm H88
Critical update for SUSE fixing 12 vulnerabilities in netty and netty-tcnative, addressing security risks.
An update that solves 12 vulnerabilities can now be installed.

Summary

## This update for netty, netty-tcnative fixes the following issues * CVE-2026-41417: missing validations leads to HTTP request smuggling and RTSP request injection via start-line injection in `DefaultHttpRequest.setUri()` (bsc#1264350). * CVE-2026-42578: HTTP Header Injection via HttpProxyHandler Disabled Validation in Netty (bsc#1265243). * CVE-2026-42579: DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding (bsc#1265272). * CVE-2026-42580: chunk size parser silently overflows int and enables request smuggling attacks (bsc#1265273). * CVE-2026-42581: TE+CL header coexistence in HTTP/1.0 requests bypasses smuggling sanitization (bsc#1265277). * CVE-2026-42583: resource exhaustion and possible denial of service via

References

* bsc#1264350

* bsc#1265243

* bsc#1265245

* bsc#1265246

* bsc#1265272

* bsc#1265273

* bsc#1265277

* bsc#1265279

* bsc#1265280

* bsc#1265292

* bsc#1265294

* bsc#1265318

Cross-

* CVE-2026-41417

* CVE-2026-42578

* CVE-2026-42579

* CVE-2026-42580

* CVE-2026-42581

* CVE-2026-42582

* CVE-2026-42583

* CVE-2026-42584

* CVE-2026-42585

* CVE-2026-42586

* CVE-2026-42587

* CVE-2026-44248

CVSS scores:

* CVE-2026-41417 ( SUSE ): 8.3

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N

* CVE-2026-41417 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N

* CVE-2026-41417 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

* CVE-2026-42578 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

* CVE-2026-42578 ( NVD ): 2.9

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:2308-1
Release Date: 2026-06-09T08:14:00Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here