Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CWE-1035 (OWASP 2017年十大分类A9-使用含有已知漏洞的组件) — Vulnerability Class 12

12 vulnerabilities classified as CWE-1035 (OWASP 2017年十大分类A9-使用含有已知漏洞的组件). AI Chinese analysis included.

CVE ID Title CVSS Severity Published
CVE-2026-93579 Io.netty/netty-codec-http2: netty: http/2 header field values are not validated by default (cr/lf/nul passthrough) — Red Hat AMQ Broker 7 6.5 Medium 2026-09-18
CVE-2026-93566 Io.netty/netty-codec-http: netty: http request smuggling due to control characters in the chunk-size line — Red Hat AMQ Broker 7 6.5 Medium 2026-09-18
CVE-2026-93565 Io.netty/netty-codec-http: netty rtspdecoder method-token smuggling via trailing control byte — Red Hat AMQ Broker 7 7.5 High 2026-09-18
CVE-2026-93564 Io.netty/netty-codec-haproxy: netty: haproxy proxy-v2 nested-tlv grandchild bytebuf reference-count leak (incomplete fix of pr #16881) — Red Hat AMQ Broker 7 7.5 High 2026-09-18
CVE-2026-93558 Io.netty/netty-codec-http: netty: unbounded per-connection queue growth in websocketserverextensionhandler leads to denial of service — Red Hat AMQ Broker 7 7.5 High 2026-09-18
CVE-2026-93560 Io.netty/netty-codec-stomp: netty: stomp codec content-length long-to-int truncation causes infinite decode loop dos — Red Hat build of Apache Camel for Spring Boot 4 7.5 High 2026-09-18
CVE-2026-93492 Io.netty/netty-codec-http2: netty: http/2 hpackencoder dos with large table size — Red Hat AMQ Broker 7 5.3 Medium 2026-09-18
CVE-2026-93563 Io.netty/netty-codec-smtp: netty: unbounded multi-line response accumulation in smtpresponsedecoder leads to memory-exhaustion dos — Red Hat build of Apache Camel for Spring Boot 4 7.5 High 2026-09-18
CVE-2026-93578 Io.netty/netty-handler-ssl-ocsp: netty: missing extended key usage (eku) check in ocsp client allows certificate revocation bypass — Red Hat build of Apache Camel for Spring Boot 4 5.9 Medium 2026-09-18
CVE-2026-93575 Io.netty/netty-codec-mqtt: netty: resource exhaustion in mqttdecoder — Red Hat AMQ Broker 7 7.5 High 2026-09-18
CVE-2026-93561 Io.netty/netty-codec-memcache: netty: memcache binary codec signed/unsigned type mismatch causes frame desynchronization and response smuggling — Red Hat build of Apache Camel for Spring Boot 4 6.5 Medium 2026-09-18
CVE-2026-93494 Io.netty/netty-codec-stomp: netty: bytebuf leak in stompsubframedecoder when a frame body is never terminated — Red Hat build of Apache Camel for Spring Boot 4 7.5 High 2026-09-18

Vulnerabilities classified as CWE-1035 (OWASP 2017年十大分类A9-使用含有已知漏洞的组件) represent 12 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.