CVE-2026-33870Patch(netty / netty)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch netty netty systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-444

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • netty

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • General: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-04-03); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
netty

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-03-25: 1Mentions · 2026-03-28: 1Mentions · 2026-04-03: 2Mentions · 2026-04-28: 1Mentions · 2026-07-17: 1Patch / Workaround · 2026-03-25: 1Patch / Workaround · 2026-03-28: 1Patch / Workaround · 2026-07-17: 1Technical Details · 2026-03-28: 1Technical Details · 2026-04-03: 2Technical Details · 2026-07-17: 103-2503-2804-0304-2807-17
Signal classification2 categories
Patch
350.0%
General
350.0%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-03-251
Patch1
2026-03-281
Patch1
2026-04-032
General2
2026-04-281
General1
2026-07-171
Patch1
Full discourse6 posts
  • Eclipse Vert.x@vertx_project
    Patch

    Eclipse Vert.x 5.0.9 / 4.5.26 have been released, fixing bugs as well as CVE-2026-33871 and CVE-2026-33870 : https://vertx.io/blog/eclipse-vert-x-5-0-9/ and https://vertx.io/blog/eclipse-vert-x-4-5-26/

    Post summary

    Eclipse Vert.x released version 5.0.9 and 4.5.26, which include patches for CVE‑2026‑33871 and CVE‑2026‑33870.

    21080316
    4.4K followersView on X
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    General

    ❌ CVE-2026-33870: Vulnerability in focus per weekly intel (CVSS 7.5). Severity: High. Published: 2026-04-03. Source: https://www.cyfirma.com/news/weekly-intelligence-report-03-april-2026

    Post summary

    The post flags CVE‑2026‑33870 as a high‑severity issue in a weekly report but offers only its CVSS score and no further technical or actionable information.

    1003033
    1.4K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Oracle ❗ CVE-2026-35229 ❗ CVE-2026-33870 ❗ CVE-2026-31790 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-oracle-2/ https://t.co/y1CAnFesIT

    Post summary

    The text lists three Oracle product vulnerabilities and directs readers to an external link for more details, but provides no additional technical or exploitation information.

    00001135
    6.7K followersView on X
  • VulniPulse@vulnipulse
    Patch

    ⚠️ NetApp OnCommand Insight alert: CVE-2026-33870 (CVSS 7.5) Attackers could disrupt service or cause a denial of service. No workaround is available; follow the vendor advisory for updates. https://vulnipulse.com/advisories/netapp-ntap-20260717-0001 #NetApp #OnCommandInsight #CyberSecurity #CVE

    Post summary

    The advisory warns of CVE-2026-33870 in NetApp OnCommand Insight, which can cause denial‑of‑service, with no workaround available and recommends following the vendor advisory for updates.

    0000032
    6 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-33870: Netty HTTP Request Smuggling Bug - What It Means for Your Business and How to Respond https://hubs.li/Q049z7YJ0

    Post summary

    The provided text references CVE‑2026‑33870, identifying it as a Netty HTTP request smuggling vulnerability, but offers no proof of concept, exploit code, active exploitation, or patches, making the content general and speculative.

    0000032
    31 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-33870 Netty is an asynchronous, event-driven network application framework. In versions prior to http://4.1.132.Final and http://4.2.10.Final, Netty incorrectly parses quoted strings in … https://www.cve.org/CVERecord?id=CVE-2026-33870

    Post summary

    CVE-2026-33870 causes Netty to incorrectly parse quoted strings, but upgrading to Netty v4.1.132.Final or v4.2.10.Final resolves the issue; no PoC, exploit, or active exploitation is reported.

    00000117
    56.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnettynetty---

Explore more