SUSE and openSUSE Address CRLF Injection Vulnerability in netty

SUSE and openSUSE Address CRLF Injection Vulnerability in netty

First seen 19 Dec 2025, 22:56 UTC Linuxsecurity 95% similarity 45.6

Article Content

Browse articles
ThreatCluster

SUSE and openSUSE released updates for netty to address a moderate security issue identified as CVE-2025-67735. The vulnerability involves a lack of URI sanitization in `HttpRequestEncoder`, which can lead to CRLF injection and potential request smuggling. The updates include enhancements and bug fixes, including an update to upstream version 4.1.130.

ThreatCluster AI

Community

Browse all →