Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

netty — Vulnerabilities & Security Advisories 99

Browse all 99 CVE security advisories affecting netty. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Netty is an asynchronous event-driven network application framework primarily utilized for developing high-performance protocol servers and clients in Java. Its widespread adoption in enterprise infrastructure makes it a critical component for many distributed systems. Historically, vulnerabilities within the framework have predominantly involved denial-of-service conditions, memory leaks, and improper input validation leading to remote code execution. While cross-site scripting is less common due to its backend focus, privilege escalation risks exist when Netty components interact with untrusted data sources. Notable incidents often stem from misconfigured handlers or outdated versions failing to patch known buffer overflow issues. Security assessments frequently highlight the importance of keeping dependencies current, as the complexity of its event loop model can obscure subtle logic flaws. Developers must rigorously validate inputs and restrict resource allocation to mitigate the risk of exploitation, ensuring that the framework’s performance benefits do not compromise system integrity.

CVE ID Title CVSS Severity Published
CVE-2026-44249 Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking — netty CWE-284 8.1 High 2026-06-11
CVE-2026-48480 netty-incubator-codec-ohttp OHttpVersionChunkDraft's Missing Final-Chunk Enforcement Leads to Undetected Stream Truncation — netty-incubator-codec-ohttp CWE-325 - - 2026-06-04
CVE-2026-48040 netty-incubator-codec-ohttp's Incorrect Native Pointer Derivation in Pooled Direct ByteBuf Fallback Leads to Out-of-Bounds Native Memory Access — netty-incubator-codec-ohttp CWE-125 - - 2026-06-04
CVE-2026-41207 netty-incubator-codec-ohttp's HPKEContext operations may produce empty byte[] on failures — netty-incubator-codec-ohttp CWE-330 - - 2026-06-04
CVE-2026-44248 Netty: Resource exhaustion in MqttDecoder — netty CWE-400 5.3 Medium 2026-05-13
CVE-2026-42587 Netty: HttpContentDecompressor maxAllocation bypass via Content-Encoding: br/zstd/snappy enables decompression bomb DoS — netty CWE-400 7.5 High 2026-05-13
CVE-2026-42586 Netty: CRLF Injection in Netty Redis Codec Encoder — netty CWE-93 6.8 Medium 2026-05-13
CVE-2026-42585 Netty: HTTP Request Smuggling due to malformed Transfer-Encoding — netty CWE-444 6.5 Medium 2026-05-13
CVE-2026-42584 Netty: HttpClientCodec response desynchronization — netty CWE-444 7.3 High 2026-05-13
CVE-2026-42583 Netty: Lz4FrameDecoder resource exhaustion — netty CWE-400 7.5 High 2026-05-13
CVE-2026-42582 Netty: HTTP/3 QPACK literal unbounded allocation — netty CWE-770 7.5 High 2026-05-13
CVE-2026-42580 Netty: HTTP Request Smuggling due to incorrect chunk size parsing — netty CWE-444 6.5 Medium 2026-05-13
CVE-2026-42579 Netty: DNS Codec Input Validation Bypass in Netty (Encoder + Decoder) — netty CWE-20 7.5 High 2026-05-13
CVE-2026-42577 Netty: epoll transport denial of service via RST on half-closed TCP connection — netty CWE-772 7.5 High 2026-05-13
CVE-2026-42578 Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation — netty CWE-113 2.9 Low 2026-05-13
CVE-2026-42581 Netty: HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization — netty CWE-444 5.8 Medium 2026-05-13
CVE-2026-41417 Netty vulnerable to HTTP request smuggling and RTSP request injection via DefaultHttpRequest.setUri() — netty CWE-93 5.3 Medium 2026-05-06
CVE-2026-33871 Netty HTTP/2 CONTINUATION Frame Flood DoS via Zero-Byte Frame Bypass — netty CWE-770 8.7 High 2026-03-27
CVE-2026-33870 Netty: HTTP Request Smuggling via Chunked Extension Quoted-String Parsing — netty CWE-444 7.5 High 2026-03-27
CVE-2025-67735 Netty has a CRLF Injection vulnerability in io.netty.handler.codec.http.HttpRequestEncoder — netty CWE-93 6.5 Medium 2025-12-16
CVE-2025-59419 Netty netty-codec-smtp SMTP Command Injection Vulnerability Allowing Email Forgery — netty CWE-93 9.8 - 2025-10-15
CVE-2025-58057 Netty's BrotliDecoder is vulnerable to DoS via zip bomb style attack — netty CWE-409 7.5AI High AI 2025-09-03
CVE-2025-58056 Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions — netty CWE-444 7.4AI High AI 2025-09-03
CVE-2025-55163 Netty MadeYouReset HTTP/2 DDoS Vulnerability — netty CWE-770 7.5AI High AI 2025-08-13
CVE-2025-29908 Netty QUIC hash collision DoS attack — netty-incubator-codec-quic CWE-407 5.3 Medium 2025-03-31
CVE-2025-25193 Denial of Service attack on windows app using Netty — netty CWE-400 5.5 Medium 2025-02-10
CVE-2025-24970 SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine — netty CWE-20 7.5 High 2025-02-10
CVE-2024-47535 Denial of Service attack on windows app using Netty — netty CWE-400 5.5 Medium 2024-11-12
CVE-2024-40642 Absent Input Validation in BinaryHttpParser in the netty incubator codec.bhttp — netty-incubator-codec-ohttp CWE-20 8.1 High 2024-07-18
CVE-2024-36121 netty-incubator-codec-ohttp's BoringSSLAEADContext Repeats Nonces — netty-incubator-codec-ohttp CWE-200 5.9 Medium 2024-06-04

This page lists every published CVE security advisory associated with netty. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.