CVE-2026-100666 | Netty prior 4.2.17.Final/4.1.137.Final HttpServerCodec pollMethod response splitting

SecurityVulns

A vulnerability marked as critical has been reported in Netty. This affects the function pollMethod of the component HttpServerCodec. Performing a manipulation results in http response splitting.

This vulnerability is known as CVE-2026-100666. Remote exploitation of the attack is possible. No exploit is available.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More