CVE-2019-10797: WSO2 Transport-HTTP

Medium severity, CVSS 6.5. EPSS: 1.3% chance of exploitation in the next 30 days.

Netty in WSO2 transport-http before v6.3.1 is vulnerable to HTTP Response Splitting due to HTTP Header validation being disabled.

Affected products

  • WSO2 Transport-HTTP: before 6.3.1 (fixed in 6.3.1)

Published 2020-02-19. Last modified 2026-06-17.