Threats Tagged 'cve-2026-59921'
View all threats tagged with 'cve-2026-59921'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-59921'
Click on any threat for detailed analysis and mitigation recommendations
Io.netty:netty codec http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder (CVE-2026-59921)CVE-2026-59921 0 CVE-2026-59921 is a CRLF injection vulnerability in Netty's HttpPostRequestEncoder component affecting versions 4.2.12.Final and earlier with codec-http multipart. The vulnerability arises because user-controlled filenames are directly concatenated into Content-Disposition MIME headers without validation or sanitization of CRLF characters. This allows attackers who can control uploaded filenames to inject arbitrary MIME headers, potentially leading to MIME header injection, content-type spoofing, and cross-site scripting (XSS) attacks. The vulnerability requires low privileges and no user interaction, with a network attack vector. No patch status is provided in the data. Join the discussion | GCVE Database | 07/22/2026, 21:52:55 UTC Added: 07/22/2026, 23:22:59 UTC |
Showing 1 to 1 of 1 result