What is CVE-2026-59919?
CVE-2026-59919 is a vulnerability in the Netty framework where the HAProxyMessageEncoder writes AF_UNIX addresses into the HAProxy V1 protocol without validating for CRLF characters, potentially leading to protocol manipulation. This affects Netty versions prior to 4.1.136.Final and 4.2.16.Final. It is recommended to upgrade to the patched versions immediately.
Azərbaycanca: CVE-2026-59919, Netty çərçivəsində HAProxyMessageEncoder funksiyasının AF_UNIX ünvanlarını yoxlamadan HAProxy V1 protokoluna CRLF simvolları ilə yazması nəticəsində yaranan təhlükəsizlik boşluğudur. Bu, 4.1.136.Final və 4.2.16.Final versiyalarından əvvəlki Netty versiyalarına təsir edir. Təsirə məruz qalan sistemlərdə protokol manipulyasiyasının qarşısını almaq üçün dərhal qeyd olunan versiyalara yeniləmə etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-20
FAQ2
In which Netty function was CVE-2026-59919 discovered?
CVE-2026-59919 is a vulnerability in the Netty framework where the HAProxyMessageEncoder writes AF_UNIX addresses into the HAProxy V1 protocol without validating for CRLF characters.
Which Netty versions are affected by CVE-2026-59919?
This affects Netty versions prior to 4.1.136.Final and 4.2.16.Final.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.