CRITICAL

CVE-2019-20444

CVSS v3

9.1

CRITICAL

EPSS Score

11.1%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an "invalid fold."

Technical details

Published
1/29/2020

Frequently asked questions

What is CVE-2019-20444?

HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an "invalid fold."

Is CVE-2019-20444 actively exploited?

Active exploitation of CVE-2019-20444 has not been confirmed. The EPSS score is 11.1%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2019-20444?

CVE-2019-20444 has a CVSS v3 base score of 9.1 (CRITICAL severity).

Is CVE-2019-20444 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.