Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

netty — Vulnerabilities & Security Advisories 99

Browse all 99 CVE security advisories affecting netty. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Netty is an asynchronous event-driven network application framework primarily utilized for developing high-performance protocol servers and clients in Java. Its widespread adoption in enterprise infrastructure makes it a critical component for many distributed systems. Historically, vulnerabilities within the framework have predominantly involved denial-of-service conditions, memory leaks, and improper input validation leading to remote code execution. While cross-site scripting is less common due to its backend focus, privilege escalation risks exist when Netty components interact with untrusted data sources. Notable incidents often stem from misconfigured handlers or outdated versions failing to patch known buffer overflow issues. Security assessments frequently highlight the importance of keeping dependencies current, as the complexity of its event loop model can obscure subtle logic flaws. Developers must rigorously validate inputs and restrict resource allocation to mitigate the risk of exploitation, ensuring that the framework’s performance benefits do not compromise system integrity.

CVE ID Title CVSS Severity Published
CVE-2026-56819 Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS) — netty CWE-400 7.5 High 2026-07-21
CVE-2026-56817 Netty: XML External Entity (XXE) injection via unconfigured XML factory when DTD and entity processing are enabled — netty CWE-611 - - 2026-07-21
CVE-2026-56816 Netty: Memory Exhaustion via HTTP/3 Reserved Frame Types — netty CWE-400 7.5 High 2026-07-21
CVE-2026-56746 Netty has a Security Control Bypass via CORS Short-Circuit Failure — netty CWE-284 6.5 Medium 2026-07-21
CVE-2026-56745 Netty SpdyHttpDecoder: ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustion — netty CWE-400 - - 2026-07-21
CVE-2026-55851 Netty codec-haproxy: Signed-Byte Sentinel Collision in HAProxyMessageDecoder Leads to Unbounded Memory Exhaustion — netty CWE-400 8.7 High 2026-07-21
CVE-2026-55833 Netty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation — netty CWE-400 7.5 High 2026-07-20
CVE-2026-55831 Netty SPDY SETTINGS frame count materializes unbounded settings map — netty CWE-770 7.5 High 2026-07-20
CVE-2026-44891 Netty: Denial of Service via Unbounded Headers in StompSubframeDecoder — netty CWE-400 7.5 High 2026-07-17
CVE-2026-50560 Netty susceptible to HTTP/2 Reset Attack with different on-the-wire signature — netty CWE-770 - - 2026-06-12
CVE-2026-50020 Netty's HttpObjectDecoder skips arbitrary initial control characters when only initial CRLF characters are permitted — netty CWE-444 5.3 Medium 2026-06-12
CVE-2026-50011 Netty has unbounded pre-allocation in RedisArrayAggregator from RESP array length — netty CWE-400 7.5 High 2026-06-12
CVE-2026-50010 Netty's wrapping plain trust manager silently disables hostname verification — netty CWE-347 7.5 High 2026-06-12
CVE-2026-50009 Netty QUIC stateless reset token material exposed through header-visible connection IDs — netty CWE-200 4.8 Medium 2026-06-12
CVE-2026-48748 Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion — netty CWE-770 7.5 High 2026-06-12
CVE-2026-48059 Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion — netty CWE-401 8.7 High 2026-06-12
CVE-2026-48043 netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion — netty CWE-400 5.3 Medium 2026-06-12
CVE-2026-48006 Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator — netty CWE-401 8.7 High 2026-06-12
CVE-2026-47691 Netty has Insufficient Bailiwick Validation for NS Records — netty CWE-345 8.7 High 2026-06-12
CVE-2026-47244 Netty HTTP/2: Advertised MAX_CONCURRENT_STREAMS are not enforced — netty CWE-400 5.3 Medium 2026-06-12
CVE-2026-46340 Netty: SCTP reassembly nests buffers without bound — netty CWE-770 7.5 High 2026-06-12
CVE-2026-45674 Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records — netty CWE-345 8.7 High 2026-06-12
CVE-2026-45673 Netty: DNS Cache Poisoning due to Predictable PRNG and Default Static Source Port — netty CWE-330 6.8 Medium 2026-06-12
CVE-2026-45536 Netty: Unix-socket fd receive leaks descriptors when peer sends two at once — netty CWE-200 4.0 Medium 2026-06-12
CVE-2026-45416 Netty: SNI handler pre-allocates up to 16 MiB from nine attacker bytes — netty CWE-770 7.5 High 2026-06-12
CVE-2026-44894 Netty's Default QUIC token handler accepts any client-supplied token — netty CWE-940 7.5 High 2026-06-12
CVE-2026-44893 Netty: HAProxy SSL TLV parsing leaks retained slice on invalid TLV length — netty CWE-703 7.5 High 2026-06-12
CVE-2026-44892 Netty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header Size — netty CWE-400 7.5 High 2026-06-12
CVE-2026-44890 Netty has Unbounded Direct Memory Consumption in its RedisDecoder — netty CWE-400 7.5 High 2026-06-11
CVE-2026-44250 Netty: Memory Exhaustion in RedisArrayAggregator due to Deeply Nested Arrays — netty CWE-400 7.5 High 2026-06-11

This page lists every published CVE security advisory associated with netty. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.