This affects the package io.jooby:jooby-netty before 1.6.9, from 2.0.0 and before 2.2.1. The DefaultHttpHeaders is set to false which means it does not validates that the header isnt being abused for HTTP Response Splitting.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Jooby | Jooby | * | 1.6.9 (excluding) |
| Jooby | Jooby | 2.0.0 (including) | 2.2.1 (excluding) |