What is CVE-2026-59920?
A vulnerability in Netty's STOMP encoder fails to escape newline characters in header values, allowing header injection attacks in CONNECT/CONNECTED frames. This affects Netty versions prior to 4.1.136.Final and 4.2.16.Final. Users should update to the patched versions immediately.
Azərbaycanca: Netty şəbəkə framework'ünün STOMP kodlayıcısında header dəyərlərində yeni sətir simvolunun ( ) filterlənməməsi zəifliyi aşkarlanıb. Bu, təsdiqlənmiş versiyalardan (4.1.136.Final və 4.2.16.Final) əvvəlki Netty istifadəçilərinə təsir edir; header injection hücumlarına yol aça bilər. İstifadəçilər dərhal qeyd olunan versiyalara yeniləmə etməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
In which component of the Netty framework was CVE-2026-59920 discovered?
The vulnerability was discovered in Netty's STOMP encoder.
To which versions should Netty users update to mitigate CVE-2026-59920?
Users should update to versions 4.1.136.Final or 4.2.16.Final.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.