CVE Explorer
CVE-2026-59919
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Final, Netty's HAProxy encoder ( HAProxyMessageEncoder ) writes AF_UNIX source and destination socket addresses into the HAProxy V1 text protocol without validating them for CRLF characters, so an attacker who controls an AF_UNIX address can inject \r\n sequences and split the single PROXY header into multiple lines. This is possible because the V1 protocol uses CRLF as its line
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"netty","vendor":"netty","versions":[{"status":"affected","version":"< 4.1.136.Final"},{"status":"affected","version":">= 4.2.0.Final, < 4.2.16.Final"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:db71944a6ed7d54d356b423c159adf8d1aa5b05ad1ffd9c6bbe33dcbbf8ed641 · sha256:cb3dc90cd3a259a6… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:db71944a6ed7d54d356b423c159adf8d1aa5b05ad1ffd9c6bbe33dcbbf8ed641 · sha256:cb3dc90cd3a259a6… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-93","description":"CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:db71944a6ed7d54d356b423c159adf8d1aa5b05ad1ffd9c6bbe33dcbbf8ed641 · sha256:cb3dc90cd3a259a6… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"tags":["exploit"],"url":"https://github.com/netty/netty/security/advisories/GHSA-wh89-7897-x99h"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:db71944a6ed7d54d356b423c159adf8d1aa5b05ad1ffd9c6bbe33dcbbf8ed641 · sha256:cb3dc90cd3a259a6… · /containers/adp/0/references/0
{"name":"https://github.com/netty/netty/security/advisories/GHSA-wh89-7897-x99h","tags":["x_refsource_CONFIRM"],"url":"https://github.com/netty/netty/security/advisories/GHSA-wh89-7897-x99h"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:db71944a6ed7d54d356b423c159adf8d1aa5b05ad1ffd9c6bbe33dcbbf8ed641 · sha256:cb3dc90cd3a259a6… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.