Netty, Cache Poisoning via CORS Vary Header Overwrite, CVE-2026-59903 (Medium) -DC-Aug2026-1543

Listen to this Post

Netty is an asynchronous, event-driven network application framework widely used to build high-performance web applications and microservices. A vulnerability exists in Netty’s `CorsHandler` component that allows an attacker to poison intermediate caches and disclose another user’s sensitive information.
The root cause lies in the `io.netty.handler.codec.http.cors.CorsHandlersetVaryHeader` method, which overwrites any existing `Vary` headers previously set by backend applications:

private static void setVaryHeader(final HttpResponse response) {
response.headers().set(HttpHeaderNames.VARY, HttpHeaderNames.ORIGIN);
}

The `set()` method replaces all existing values for a given header rather than appending to them. When a backend application sets a `Vary` header—such as `Vary: Authorization` or Vary: Cookie—to ensure that intermediate caches (like CDNs) store responses separately per user based on their authentication context, the `CorsHandler` silently overwrites it with Vary: origin.
This causes the caching proxy to ignore the authorization context and cache the response based solely on the URL and `Origin` header. An attacker can then force the cache to store a response under a specific Origin, and later retrieve that cached response—which may contain another user’s sensitive data—by making a request with the same Origin. The vulnerability affects all Netty-based applications that use the CorsHandler, set custom `Vary` headers for caching authenticated or user-specific responses, and are deployed behind a caching proxy or CDN. It is fixed in Netty versions 4.1.137.Final and 4.2.17.Final.

DailyCVE Form:

Platform: Netty
Version: <4.1.137.Final, 4.2.0-4.2.16.Final
Vulnerability: Cache Poisoning / Info Disclosure
Severity: Medium (CVSS 6.5)
Date: 2026-08-17

Prediction: Patch available (4.1.137.Final / 4.2.17.Final)

What Undercode Say:

Check your Netty version in Maven pom.xml
mvn dependency:tree | grep netty-codec-http
Check version in Gradle build.gradle
./gradlew dependencies | grep netty-codec-http
Detect vulnerable versions (example script)
VERSION=$(mvn help:evaluate -Dexpression=project.version -q -DforceStdout | grep -oE '4.[0-9]+.[0-9]+.Final')
if [[ "$VERSION" < "4.1.137.Final" ]] || [[ "$VERSION" =~ ^4.2.[0-9]+.Final$ && "$VERSION" < "4.2.17.Final" ]]; then
echo "Vulnerable to CVE-2026-59903"
else
echo "Not vulnerable"
fi

Analytics:

  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Confidentiality Impact: High (sensitive data exposure)
  • CWE: CWE-524 – Use of Cache Containing Sensitive Information

Exploit: (Educational Purposes!)

  1. Identify a target Netty-based application behind a CDN that uses `CorsHandler` and sets `Vary: Authorization` or Vary: Cookie.
  2. As an attacker, send a request with a malicious `Origin` header (e.g., Origin: https://attacker.com`) to a sensitive endpoint. The `CorsHandler` overwrites the `Vary: Authorization` header withVary: origin`.
  3. The caching proxy now caches the response keyed only by URL and Origin, ignoring the user’s authorization context.
  4. A victim user later makes a request to the same endpoint with the same `Origin` value. The cache serves the attacker’s previously cached response to the victim, or the victim’s response is cached and later retrieved by the attacker.
  5. The attacker can now access the cached response containing the victim’s sensitive data by making a request with the matching Origin.

    Protection:

– Upgrade Netty to version 4.1.137.Final or 4.2.17.Final immediately.
– If upgrading is not immediately possible, avoid using `CorsHandler` with applications that rely on custom `Vary` headers for cache isolation.
– Implement a custom `CorsHandler` that checks for existing `Vary` headers and appends `Origin` instead of overwriting them.
– Configure your CDN or caching proxy to ignore the `Vary` header from the origin server or to cache based on additional criteria like authentication tokens.

Impact:

– Cache Poisoning – An attacker can poison the cache with responses that are then served to other users.
– Information Disclosure – Sensitive user data (personal information, session tokens, etc.) can be leaked to unauthorized actors.
– Affected Systems – Any Netty-based web application that uses CorsHandler, sets custom `Vary` headers, and is deployed behind a caching proxy or CDN.
– End-User Impact – End-users of affected applications are at risk of having their sensitive data exposed.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top