CVSS v3
9.1
CRITICAL
EPSS Score
11.1%
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an "invalid fold."
HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an "invalid fold."
Active exploitation of CVE-2019-20444 has not been confirmed. The EPSS score is 11.1%, indicating the estimated probability of exploitation in the next 30 days.
CVE-2019-20444 has a CVSS v3 base score of 9.1 (CRITICAL severity).
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
Ranked by exploit probability (EPSS).