CVE-2026-75595
- EPSS 0.32%
- Veröffentlicht 19.08.2026 21:17:37
- Zuletzt bearbeitet 20.08.2026 15:18:38
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.handler.ssl.SslClientHelloHandler#decode checks the wrong offset before reading the four-byte TLS handshake header, so a ClientHell...
CVE-2026-75596
- EPSS 0.35%
- Veröffentlicht 19.08.2026 20:56:21
- Zuletzt bearbeitet 20.08.2026 20:17:46
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, the default io.netty.handler.ssl.SniHandler constructors use the pre-handshake ClientHello aggregation path in handler/src/main/java/io/net...
CVE-2026-59903
- EPSS 0.4%
- Veröffentlicht 17.08.2026 17:56:28
- Zuletzt bearbeitet 17.08.2026 19:16:32
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.http.cors.CorsHandler setVaryHeader replaces application Vary headers such as Authorization or Cookie with Origin, a...
CVE-2026-59902
- EPSS 0.68%
- Veröffentlicht 17.08.2026 17:48:55
- Zuletzt bearbeitet 18.08.2026 15:16:55
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.sctp.SctpMessageCompletionHandler limits incomplete messages and fragment counts but not maxBufferedBytes, allowing ...
CVE-2026-73508
- EPSS 0.33%
- Veröffentlicht 13.08.2026 14:27:20
- Zuletzt bearbeitet 13.08.2026 18:18:17
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.dns.AbstractDnsRecord, io.netty.handler.codec.dns.DefaultDnsRecordDecoder.decodeRecord(), and io.netty.handler.codec...
CVE-2026-73507
- EPSS 0.46%
- Veröffentlicht 13.08.2026 14:25:34
- Zuletzt bearbeitet 15.08.2026 04:18:25
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.xml.XmlFrameDecoder.decode() failed to preserve closing-tag parser state across invocations, so an unauthenticated r...
CVE-2026-56818
- EPSS 0.47%
- Veröffentlicht 07.08.2026 17:14:02
- Zuletzt bearbeitet 08.08.2026 04:17:47
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the RedisArrayAggregator Redis codec clears retained partial aggregate state when the maxNestedArrayDepth limit is exceeded, but it does no...
CVE-2026-59898
- EPSS 0.25%
- Veröffentlicht 29.07.2026 18:02:07
- Zuletzt bearbeitet 06.08.2026 20:35:23
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ab attacker can force WebSocket upgrade via the lax V07 (or V08) handshaker by sending `Sec-WebSocket-Version: 7` and omitting `C...
CVE-2026-59899
- EPSS 0.34%
- Veröffentlicht 29.07.2026 18:00:37
- Zuletzt bearbeitet 06.08.2026 20:25:31
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, `HttpContentEncoder` (the superclass of the production handler `HttpContentCompressor`) maintains a per-channel `ArrayDeque<CharSe...
CVE-2026-59900
- EPSS 0.23%
- Veröffentlicht 29.07.2026 17:58:35
- Zuletzt bearbeitet 06.08.2026 20:29:01
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, Netty's HTTP/2-to-HTTP/1.x translation layer (`Http2StreamFrameToHttpObjectCodec` and `InboundHttp2ToHttpAdapter`) fails to dedupl...