A vulnerability, which was classified as problematic, was found in Netty. This issue affects the function setFilename of the component HttpPostRequestEncoder. The manipulation results in crlf injection.

This vulnerability is identified as CVE-2026-59921. The attack can be executed remotely. There is not any exploit available.

You should upgrade the affected component.