A vulnerability labeled as critical has been found in netty netty-codec-http up to 4.1.133.Final/4.2.13.Final. This impacts the function queue.poll. The manipulation results in http request smuggling.

This vulnerability is reported as CVE-2026-42584. The attack can be launched remotely. No exploit exists.

The affected component should be upgraded.