What is CVE-2026-59898?
CVE-2026-59898 is a vulnerability in Netty's lax V07/V08 WebSocket handshaker. An attacker can force a WebSocket upgrade by sending `Sec-WebSocket-Version: 7` and omitting the `Connection: Upgrade`/`Upgrade: websocket` headers. Versions prior to 4.1.136.Final and 4.2.16.Final are affected, and upgrading is required.
Azərbaycanca: CVE-2026-59898, Netty framework-də V07/V08 WebSocket handshaker-də zəiflikdir. Təcavüzkar xüsusi `Sec-WebSocket-Version: 7` başlığı göndərməklə və `Connection: Upgrade`/`Upgrade: websocket` başlıqlarını çıxarmaqla WebSocket əlaqəsini məcburi şəkildə qura bilər. 4.1.136.Final və 4.2.16.Final versiyalarından əvvəlki versiyalar təsirlənir, yeniləmə tətbiq edilməlidir.
FAQ2
Which framework is affected by CVE-2026-59898?
CVE-2026-59898 affects the Netty framework.
Which versions should I upgrade to in order to mitigate CVE-2026-59898?
To mitigate this vulnerability, you need to upgrade the Netty framework to version 4.1.136.Final or 4.2.16.Final.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.