Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

netty — Vulnerabilities & Security Advisories 99

Browse all 99 CVE security advisories affecting netty. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Netty is an asynchronous event-driven network application framework primarily utilized for developing high-performance protocol servers and clients in Java. Its widespread adoption in enterprise infrastructure makes it a critical component for many distributed systems. Historically, vulnerabilities within the framework have predominantly involved denial-of-service conditions, memory leaks, and improper input validation leading to remote code execution. While cross-site scripting is less common due to its backend focus, privilege escalation risks exist when Netty components interact with untrusted data sources. Notable incidents often stem from misconfigured handlers or outdated versions failing to patch known buffer overflow issues. Security assessments frequently highlight the importance of keeping dependencies current, as the complexity of its event loop model can obscure subtle logic flaws. Developers must rigorously validate inputs and restrict resource allocation to mitigate the risk of exploitation, ensuring that the framework’s performance benefits do not compromise system integrity.

Found 91 results / 99 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-44248 Netty: Resource exhaustion in MqttDecoder — netty CWE-400 5.3 Medium 2026-05-13
CVE-2026-42587 Netty: HttpContentDecompressor maxAllocation bypass via Content-Encoding: br/zstd/snappy enables decompression bomb DoS — netty CWE-400 7.5 High 2026-05-13
CVE-2026-42586 Netty: CRLF Injection in Netty Redis Codec Encoder — netty CWE-93 6.8 Medium 2026-05-13
CVE-2026-42585 Netty: HTTP Request Smuggling due to malformed Transfer-Encoding — netty CWE-444 6.5 Medium 2026-05-13
CVE-2026-42584 Netty: HttpClientCodec response desynchronization — netty CWE-444 7.3 High 2026-05-13
CVE-2026-42583 Netty: Lz4FrameDecoder resource exhaustion — netty CWE-400 7.5 High 2026-05-13
CVE-2026-42582 Netty: HTTP/3 QPACK literal unbounded allocation — netty CWE-770 7.5 High 2026-05-13
CVE-2026-42580 Netty: HTTP Request Smuggling due to incorrect chunk size parsing — netty CWE-444 6.5 Medium 2026-05-13
CVE-2026-42579 Netty: DNS Codec Input Validation Bypass in Netty (Encoder + Decoder) — netty CWE-20 7.5 High 2026-05-13
CVE-2026-42577 Netty: epoll transport denial of service via RST on half-closed TCP connection — netty CWE-772 7.5 High 2026-05-13
CVE-2026-42578 Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation — netty CWE-113 2.9 Low 2026-05-13
CVE-2026-42581 Netty: HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization — netty CWE-444 5.8 Medium 2026-05-13
CVE-2026-41417 Netty vulnerable to HTTP request smuggling and RTSP request injection via DefaultHttpRequest.setUri() — netty CWE-93 5.3 Medium 2026-05-06
CVE-2026-33871 Netty HTTP/2 CONTINUATION Frame Flood DoS via Zero-Byte Frame Bypass — netty CWE-770 8.7 High 2026-03-27
CVE-2026-33870 Netty: HTTP Request Smuggling via Chunked Extension Quoted-String Parsing — netty CWE-444 7.5 High 2026-03-27
CVE-2025-67735 Netty has a CRLF Injection vulnerability in io.netty.handler.codec.http.HttpRequestEncoder — netty CWE-93 6.5 Medium 2025-12-16
CVE-2025-59419 Netty netty-codec-smtp SMTP Command Injection Vulnerability Allowing Email Forgery — netty CWE-93 9.8 - 2025-10-15
CVE-2025-58057 Netty's BrotliDecoder is vulnerable to DoS via zip bomb style attack — netty CWE-409 7.5AI High AI 2025-09-03
CVE-2025-58056 Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions — netty CWE-444 7.4AI High AI 2025-09-03
CVE-2025-55163 Netty MadeYouReset HTTP/2 DDoS Vulnerability — netty CWE-770 7.5AI High AI 2025-08-13
CVE-2025-25193 Denial of Service attack on windows app using Netty — netty CWE-400 5.5 Medium 2025-02-10
CVE-2025-24970 SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine — netty CWE-20 7.5 High 2025-02-10
CVE-2024-47535 Denial of Service attack on windows app using Netty — netty CWE-400 5.5 Medium 2024-11-12
CVE-2024-29025 Netty HttpPostRequestDecoder can OOM — netty CWE-770 5.3 Medium 2024-03-25
CVE-2023-34462 netty-handler SniHandler 16MB allocation — netty CWE-400 6.5 Medium 2023-06-22
CVE-2022-41915 Netty 安全漏洞 — netty CWE-436 6.5 Medium 2022-12-13
CVE-2022-41881 Netty 安全漏洞 — netty CWE-674 5.3 Medium 2022-12-12
CVE-2022-24823 Local Information Disclosure Vulnerability in io.netty:netty-codec-http — netty CWE-668 5.5 Medium 2022-05-06
CVE-2021-43797 HTTP fails to validate against control chars in header names which may lead to HTTP request smuggling — netty CWE-444 6.5 Medium 2021-12-09
CVE-2021-21409 Possible request smuggling in HTTP/2 due missing validation of content-length — netty CWE-444 5.9 Medium 2021-03-30

This page lists every published CVE security advisory associated with netty. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.