A vulnerability labeled as critical has been found in netty netty-codec-http up to 4.1.133.Final/4.2.13.Final. This impacts the function
queue.poll. The manipulation results in http request smuggling.
This vulnerability is reported as CVE-2026-42584. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.