Listen to this Post
Netty is an asynchronous, event-driven network application framework widely used to build high-performance web applications and microservices. A vulnerability exists in Netty’s `CorsHandler` component that allows an attacker to poison intermediate caches and disclose another user’s sensitive information.
The root cause lies in the `io.netty.handler.codec.http.cors.CorsHandlersetVaryHeader` method, which overwrites any existing `Vary` headers previously set by backend applications:
private static void setVaryHeader(final HttpResponse response) {
response.headers().set(HttpHeaderNames.VARY, HttpHeaderNames.ORIGIN);
}
The `set()` method replaces all existing values for a given header rather than appending to them. When a backend application sets a `Vary` header—such as `Vary: Authorization` or Vary: Cookie—to ensure that intermediate caches (like CDNs) store responses separately per user based on their authentication context, the `CorsHandler` silently overwrites it with Vary: origin.
This causes the caching proxy to ignore the authorization context and cache the response based solely on the URL and `Origin` header. An attacker can then force the cache to store a response under a specific Origin, and later retrieve that cached response—which may contain another user’s sensitive data—by making a request with the same Origin. The vulnerability affects all Netty-based applications that use the CorsHandler, set custom `Vary` headers for caching authenticated or user-specific responses, and are deployed behind a caching proxy or CDN. It is fixed in Netty versions 4.1.137.Final and 4.2.17.Final.
DailyCVE Form:
Platform: Netty
Version: <4.1.137.Final, 4.2.0-4.2.16.Final
Vulnerability: Cache Poisoning / Info Disclosure
Severity: Medium (CVSS 6.5)
Date: 2026-08-17
Prediction: Patch available (4.1.137.Final / 4.2.17.Final)
What Undercode Say:
Check your Netty version in Maven pom.xml mvn dependency:tree | grep netty-codec-http Check version in Gradle build.gradle ./gradlew dependencies | grep netty-codec-http Detect vulnerable versions (example script) VERSION=$(mvn help:evaluate -Dexpression=project.version -q -DforceStdout | grep -oE '4.[0-9]+.[0-9]+.Final') if [[ "$VERSION" < "4.1.137.Final" ]] || [[ "$VERSION" =~ ^4.2.[0-9]+.Final$ && "$VERSION" < "4.2.17.Final" ]]; then echo "Vulnerable to CVE-2026-59903" else echo "Not vulnerable" fi
Analytics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Confidentiality Impact: High (sensitive data exposure)
- CWE: CWE-524 – Use of Cache Containing Sensitive Information
Exploit: (Educational Purposes!)
- Identify a target Netty-based application behind a CDN that uses `CorsHandler` and sets `Vary: Authorization` or
Vary: Cookie. - As an attacker, send a request with a malicious `Origin` header (e.g.,
Origin: https://attacker.com`) to a sensitive endpoint. The `CorsHandler` overwrites the `Vary: Authorization` header withVary: origin`. - The caching proxy now caches the response keyed only by URL and
Origin, ignoring the user’s authorization context. - A victim user later makes a request to the same endpoint with the same `Origin` value. The cache serves the attacker’s previously cached response to the victim, or the victim’s response is cached and later retrieved by the attacker.
- The attacker can now access the cached response containing the victim’s sensitive data by making a request with the matching
Origin.
Protection:
– Upgrade Netty to version 4.1.137.Final or 4.2.17.Final immediately.
– If upgrading is not immediately possible, avoid using `CorsHandler` with applications that rely on custom `Vary` headers for cache isolation.
– Implement a custom `CorsHandler` that checks for existing `Vary` headers and appends `Origin` instead of overwriting them.
– Configure your CDN or caching proxy to ignore the `Vary` header from the origin server or to cache based on additional criteria like authentication tokens.
Impact:
– Cache Poisoning – An attacker can poison the cache with responses that are then served to other users.
– Information Disclosure – Sensitive user data (personal information, session tokens, etc.) can be leaked to unauthorized actors.
– Affected Systems – Any Netty-based web application that uses CorsHandler, sets custom `Vary` headers, and is deployed behind a caching proxy or CDN.
– End-User Impact – End-users of affected applications are at risk of having their sensitive data exposed.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

