---
id: CVE-2026-59903
title: 'Netty is an asynchronous, event-driven network application framework'
summary: >-
  Netty is an asynchronous, event-driven network application framework. Prior to
  4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.http.cors.CorsHandler
  setVaryHeader replaces application Vary headers such as Authorization or
  Cookie w…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N'
cwe:
  - CWE-524
  - CWE-444
vendor: netty
product: netty
affected:
  - netty < 4.1.137
  - 'netty >= 4.2.0, < 4.2.17'
patched:
  - netty 4.2.17
published: '2026-08-17'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T15:21:27.670'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-59903'
references:
  - url: 'https://github.com/netty/netty/pull/17213'
    label: security-advisories@github.com
  - url: 'https://github.com/netty/netty/pull/17217'
    label: security-advisories@github.com
  - url: 'https://github.com/netty/netty/releases/tag/netty-4.1.137.Final'
    label: security-advisories@github.com
  - url: 'https://github.com/netty/netty/releases/tag/netty-4.2.17.Final'
    label: security-advisories@github.com
  - url: 'https://github.com/netty/netty/security/advisories/GHSA-8c42-7qj2-3j46'
    label: security-advisories@github.com
  - url: 'https://github.com/advisories/GHSA-8c42-7qj2-3j46'
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59903.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-59903'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2517538'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-59903'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-59903'
tags:
  - nvd
  - exploit-available
  - ghsa
  - maven
  - csaf
  - vex
  - red-hat
epss: 0.00246
epssPercentile: 0.14123
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/xiaoqiMikko/netty-http-check'
  checkedAt: '2026-09-26T09:05:52.973Z'
exploitAvailable: true
aliases:
  - GHSA-8c42-7qj2-3j46
ecosystem: maven
ingestedAt: '2026-08-17T18:59:03.411Z'
---

## Overview

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.http.cors.CorsHandler setVaryHeader replaces application Vary headers such as Authorization or Cookie with Origin, allowing a caching proxy or CDN to reuse authenticated responses across users and disclose sensitive information. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.

## Affected

- `netty < 4.1.137`
- `netty >= 4.2.0, < 4.2.17`

## Remediation

Upgrade past the affected range:

- `netty 4.2.17`

## Package advisory (CVE-2026-59903)

Affected packages:

- `io.netty:netty-codec-http >= 4.2.0.Final, <= 4.2.16.Final`
- `io.netty:netty-codec-http <= 4.1.136.Final`

Patched in:

- `io.netty:netty-codec-http 4.2.17.Final`
- `io.netty:netty-codec-http 4.1.137.Final`

Source: https://github.com/advisories/GHSA-8c42-7qj2-3j46

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Red Hat Ceph Storage 6, Red Hat Ceph Storage 7, Red Hat Ceph Storage 8, Red Hat Ceph Storage 9, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Offline Knowledge Portal, … · no fix planned: Red Hat Ceph Storage 6, Red Hat Ceph Storage 7, Red Hat Ceph Storage 8, Red Hat Ceph Storage 9, … · updated 2026-09-23 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59903.json)
