CVE-2026-59901
- EPSS 0.26%
- Veröffentlicht 29.07.2026 17:48:39
- Zuletzt bearbeitet 06.08.2026 20:29:27
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the `Bzip2Decoder` handler in Netty's compression codec pipeline is vulnerable to a denial-of-service attack through a malformed b...
CVE-2026-59919
- EPSS 0.11%
- Veröffentlicht 29.07.2026 17:37:49
- Zuletzt bearbeitet 06.08.2026 20:33:28
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Final, Netty's HAProxy encoder ( HAProxyMessageEncoder ) writes AF_UNIX source and destination socket addresses into the HAProxy V1 te...
CVE-2026-59920
- EPSS 0.24%
- Veröffentlicht 29.07.2026 17:32:46
- Zuletzt bearbeitet 06.08.2026 20:34:47
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Final, Netty's STOMP encoder ( StompSubframeEncoder ) does not escape or validate header values in CONNECT and CONNECTED frames, s...
CVE-2026-56822
- EPSS 0.11%
- Veröffentlicht 28.07.2026 23:17:17
- Zuletzt bearbeitet 07.08.2026 15:05:31
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator forwards the SslHandshakeCompletionEvent before the asynchronous OCSP validation completes. Thi...
CVE-2026-56821
- EPSS 0.14%
- Veröffentlicht 28.07.2026 23:07:13
- Zuletzt bearbeitet 07.08.2026 15:05:53
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator flags an out-of-date OCSP response but does not stop processing it, so an expired GOOD response...
CVE-2026-59921
- EPSS 0.47%
- Veröffentlicht 28.07.2026 22:28:51
- Zuletzt bearbeitet 07.08.2026 15:05:47
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, HttpPostRequestEncoder constructs multipart HTTP request bodies by directly concatenating user-supplied filenames and field names ...
CVE-2026-56820
- EPSS 0.18%
- Veröffentlicht 21.07.2026 22:26:16
- Zuletzt bearbeitet 30.07.2026 14:48:49
Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final, `OcspClient` does not validate that the `CertificateID` in an OCSP response matches the...
CVE-2026-56816
- EPSS 0.52%
- Veröffentlicht 21.07.2026 22:17:14
- Zuletzt bearbeitet 07.08.2026 20:47:16
Netty is a network application framework for development of protocol servers and clients. Prior to 4.2.16.Final, Netty's `Http3FrameCodec` buffers incoming data for HTTP/3 reserved frame types up to the wire-specified payload length without limits; `...
CVE-2026-56746
- EPSS 0.38%
- Veröffentlicht 21.07.2026 22:17:14
- Zuletzt bearbeitet 30.07.2026 14:47:53
Netty is a network application framework for development of protocol servers and clients. Versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, are vulnerable to security control bypass during the origin evaluation process....
CVE-2026-56819
- EPSS 0.37%
- Veröffentlicht 21.07.2026 22:11:17
- Zuletzt bearbeitet 30.07.2026 14:46:35
Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, a remote unauthenticated peer can leak one direct `ByteBuf` per HTTP/2 `DATA...