What is CVE-2026-59921?
The CVE-2026-59921 vulnerability in the Netty framework occurs because HttpPostRequestEncoder directly concatenates user-supplied filenames and field names into Content-Disposition MIME headers without validation. This can lead to header injection attacks, affecting versions prior to 4.1.136.Final and 4.2.16.Final. Upgrading Netty to the latest version is recommended to mitigate this issue.
Azərbaycanca: Netty framework-də aşkar edilən CVE-2026-59921 zəifliyi, HttpPostRequestEncoder-in istifadəçi tərəfindən təqdim olunan fayl adlarını və sahə adlarını Content-Disposition MIME başlıqlarına birbaşa əlavə etməsi ilə bağlıdır. Bu, header injection hücumlarına səbəb ola bilər; 4.1.136.Final və 4.2.16.Final versiyalarından əvvəlki versiyalar təsirlənir. Problemi aradan qaldırmaq üçün Netty-ni ən son versiyaya yeniləmək tövsiyə olunur.
FAQ1
Which component in the Netty framework contains the CVE-2026-59921 vulnerability that can lead to a header injection attack?
The vulnerability is in the HttpPostRequestEncoder component, as it directly concatenates user-supplied filenames and field names into Content-Disposition MIME headers.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.