Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling.
https://www.debian.org/security/2020/dsa-4597
https://usn.ubuntu.com/4532-1/
https://seclists.org/bugtraq/2020/Jan/6
https://lists.debian.org/debian-lts-announce/2020/09/msg00004.html
https://lists.debian.org/debian-lts-announce/2020/02/msg00018.html
https://lists.debian.org/debian-lts-announce/2019/09/msg00035.html
https://github.com/netty/netty/issues/9571
https://github.com/netty/netty/compare/netty-4.1.41.Final...netty-4.1.42.Final
https://access.redhat.com/errata/RHSA-2020:0445
https://access.redhat.com/errata/RHSA-2020:0164
https://access.redhat.com/errata/RHSA-2020:0161
https://access.redhat.com/errata/RHSA-2020:0160
https://access.redhat.com/errata/RHSA-2020:0159