Netty netty-codec-smtp — SMTP command-name field is not CRLF-validated (incomplete fix of CVE-2025-59419)
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat build of Apache Camel for Spring Boot 4 | - |
cpe:/a:redhat:camel_spring_boot:4
|
|
| Red Hat | Red Hat Fuse 7 | - |
cpe:/a:redhat:jboss_fuse:7
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 | - |
cpe:/a:redhat:jboss_enterprise_application_platform:7
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 | - |
cpe:/a:redhat:jboss_enterprise_application_platform:7
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 | - |
cpe:/a:redhat:jboss_enterprise_application_platform:7
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 | - |
cpe:/a:redhat:jboss_enterprise_application_platform:7
|
|
| Red Hat | Red Hat Single Sign-On 7 | - |
cpe:/a:redhat:red_hat_single_sign_on:7
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93569 | 8.2 HIGH | Io.netty/netty-codec-http2: http/1 absolute-form host mismatch is translated to http/2 :au |
| CVE-2026-93572 | 7.5 HIGH | Io.netty/netty-codec-redis: netty: redisarrayaggregator nested resp headers multiply patch |
| CVE-2026-93575 | 7.5 HIGH | Io.netty/netty-codec-mqtt: netty: resource exhaustion in mqttdecoder |
| CVE-2026-93565 | 7.5 HIGH | Io.netty/netty-codec-http: netty rtspdecoder method-token smuggling via trailing control b |
| CVE-2026-93564 | 7.5 HIGH | Io.netty/netty-codec-haproxy: netty: haproxy proxy-v2 nested-tlv grandchild bytebuf refere |
| CVE-2026-93558 | 7.5 HIGH | Io.netty/netty-codec-http: netty: unbounded per-connection queue growth in websocketserver |
| CVE-2026-93560 | 7.5 HIGH | Io.netty/netty-codec-stomp: netty: stomp codec content-length long-to-int truncation cause |
| CVE-2026-93567 | 7.5 HIGH | Io.netty/netty-codec-http2: http/1 authority-form connect is translated to malformed http/ |
| CVE-2026-87743 | 7.5 HIGH | Quarkus-vertx-http: authorization bypass via path normalization discrepancy in quarkus htt |
| CVE-2026-93568 | 7.5 HIGH | Io.netty/netty-codec-http2: io.netty/netty-codec-http3: netty: http/2 and http/3 extended |
| CVE-2026-93491 | 7.5 HIGH | Io.netty/netty-codec-http: netty: denial of service via unbounded httpservercodec http/1.1 |
| CVE-2026-93488 | 7.5 HIGH | Io.netty/netty-codec-http: netty: denial of service via unbounded concurrent spdy streams |
| CVE-2026-91149 | 7.5 HIGH | Cockpit: cockpit: denial of service via unbounded connection thread spawning |
| CVE-2026-93563 | 7.5 HIGH | Io.netty/netty-codec-smtp: netty: unbounded multi-line response accumulation in smtprespon |
| CVE-2026-93494 | 7.5 HIGH | Io.netty/netty-codec-stomp: netty: bytebuf leak in stompsubframedecoder when a frame body |
| CVE-2026-89059 | 7.5 HIGH | Resteasy-core: resteasy: iioimageprovider unbounded image decode (decompression-bomb dos) |
| CVE-2026-89058 | 7.4 HIGH | Resteasy-core: resteasy: corsfilter reflects arbitrary origin with credentials under wildc |
| CVE-2026-81627 | 6.7 MEDIUM | Qemu-kvm: vapic writable rom alias can escape the option-rom window and expose locked smra |
| CVE-2026-93561 | 6.5 MEDIUM | Io.netty/netty-codec-memcache: netty: memcache binary codec signed/unsigned type mismatch |
| CVE-2026-93566 | 6.5 MEDIUM | Io.netty/netty-codec-http: netty: http request smuggling due to control characters in the |
Showing top 20 of 37 CVEs. View all on vendor page → →
No comments yet