Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

netty — Vulnerabilities & Security Advisories 99

Browse all 99 CVE security advisories affecting netty. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Netty is an asynchronous event-driven network application framework primarily utilized for developing high-performance protocol servers and clients in Java. Its widespread adoption in enterprise infrastructure makes it a critical component for many distributed systems. Historically, vulnerabilities within the framework have predominantly involved denial-of-service conditions, memory leaks, and improper input validation leading to remote code execution. While cross-site scripting is less common due to its backend focus, privilege escalation risks exist when Netty components interact with untrusted data sources. Notable incidents often stem from misconfigured handlers or outdated versions failing to patch known buffer overflow issues. Security assessments frequently highlight the importance of keeping dependencies current, as the complexity of its event loop model can obscure subtle logic flaws. Developers must rigorously validate inputs and restrict resource allocation to mitigate the risk of exploitation, ensuring that the framework’s performance benefits do not compromise system integrity.

CVE ID Title CVSS Severity Published
CVE-2026-100666 Netty 4.2.0 through 4.2.16 Response Desynchronization via HttpServerCodec — netty CWE-444 7.3 High 2026-09-26
CVE-2026-100665 Netty 4.2.11 through 4.2.17 QUIC Hostname Verification Bypass — netty CWE-295 7.5 High 2026-09-26
CVE-2026-100664 Netty 4.2.2 through 4.2.17 HTTP/1 Host Header Authority Confusion — netty CWE-20 7.5 High 2026-09-26
CVE-2026-100663 Netty HTTP/1 CONNECT authority-form mistranslated to malformed HTTP/3 — netty CWE-20 7.5 High 2026-09-26
CVE-2026-100662 Netty HTTP/3 QPACK encoder-stream unbounded memory exhaustion DoS — netty CWE-400 7.5 High 2026-09-26
CVE-2026-100660 Netty before 4.2.18.Final QpackEncoder Unbounded Memory Retention — netty CWE-770 7.5 High 2026-09-26
CVE-2026-100661 Netty HTTP/3 QPACK Prefixed Integer DoS via Unbounded Accumulation — netty CWE-400 7.5 High 2026-09-26
CVE-2026-100659 Netty 4.2.0 through 4.2.17 HTTP/3 Request Routing Bypass — netty CWE-444 6.5 Medium 2026-09-26
CVE-2026-54251 netty-incubator-codec-ohttp: [OHttpServerCodec] Native Direct-Memory Leak on AEAD Decryption Failure Leads to Gateway Denial of Service — netty-incubator-codec-ohttp CWE-664 8.7 High 2026-09-15
CVE-2026-89044 Netty 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final HTTP Request Smuggling via Transfer-Encoding — netty CWE-444 6.5 Medium 2026-09-10
CVE-2026-76816 Netty: MQTT Topic Name and Client ID Validation Bypass — netty CWE-20 3.5 Low 2026-08-24
CVE-2026-62380 Netty before 4.2.16.Final SOCKS Proxy Null Byte Injection — netty CWE-626 6.3 Medium 2026-08-22
CVE-2026-62243 Netty 4.2.0 through 4.2.16 TLS Hostname Verification Bypass — netty CWE-297 7.5 High 2026-08-22
CVE-2026-75595 Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext — netty CWE-754 9.1 Critical 2026-08-19
CVE-2026-75596 Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing — netty CWE-407 8.7 High 2026-08-19
CVE-2026-59903 Netty: Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite — netty CWE-524 6.5 Medium 2026-08-17
CVE-2026-59902 Netty: Memory Exhaustion in SctpMessageCompletionHandler — netty CWE-400 7.5 High 2026-08-17
CVE-2026-73508 Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names — netty CWE-772 5.3 Medium 2026-08-13
CVE-2026-73507 Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion — netty CWE-400 7.5 High 2026-08-13
CVE-2026-56818 Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state — netty CWE-401 6.5 Medium 2026-08-07
CVE-2026-59898 Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation — netty CWE-444 6.3 Medium 2026-07-29
CVE-2026-59899 Netty HttpContentEncoder: Unbounded Per-Connection Queue Growth via HTTP/1.1 Pipelining Leads to Denial of Service — netty CWE-770 6.9 Medium 2026-07-29
CVE-2026-59900 Netty codec-http2: Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass — netty CWE-444 6.9 Medium 2026-07-29
CVE-2026-59901 Netty Bzip2Decoder: Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang — netty CWE-835 8.7 High 2026-07-29
CVE-2026-59919 Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address — netty CWE-93 5.5 Medium 2026-07-29
CVE-2026-59920 Netty: STOMP CONNECT Frame Header Injection — netty CWE-93 6.5 Medium 2026-07-29
CVE-2026-56822 Netty: TOCTOU in OcspServerCertificateValidator — netty CWE-367 7.4 High 2026-07-28
CVE-2026-56821 Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator — netty CWE-299 7.4 High 2026-07-28
CVE-2026-59921 Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder — netty CWE-93 5.7 Medium 2026-07-28
CVE-2026-56820 Netty: Missing CertificateID Validation in OCSP Response Allows Replay Attacks — netty CWE-295 7.4 High 2026-07-21

This page lists every published CVE security advisory associated with netty. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.