CVE-2026-100656
- EPSS 0.43%
- Veröffentlicht 26.09.2026 13:23:24
- Zuletzt bearbeitet 28.09.2026 22:17:30
Rejected reason: This CVE ID has been rejected as a duplicate.
CVE-2026-100655
- EPSS 0.25%
- Veröffentlicht 26.09.2026 13:23:23
- Zuletzt bearbeitet 28.09.2026 22:17:30
Rejected reason: This CVE ID has been rejected as a duplicate.
CVE-2026-89044
- EPSS 0.25%
- Veröffentlicht 10.09.2026 17:39:34
- Zuletzt bearbeitet 18.09.2026 18:17:39
Netty versions 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final fail to properly validate the final transfer coding in the Transfer-Encoding header, allowing attackers to smuggle requests by using malformed encoding declarati...
CVE-2026-76816
- EPSS 0.17%
- Veröffentlicht 24.08.2026 19:53:12
- Zuletzt bearbeitet 09.09.2026 21:06:39
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.137.Final and 4.2.17.Final, MqttEncoder does not validate client identifiers, will topics, usernames, and PUBLISH topic names before encoding, allowing prohib...
CVE-2026-62243
- EPSS 0.16%
- Veröffentlicht 22.08.2026 13:16:39
- Zuletzt bearbeitet 10.09.2026 20:46:19
Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final and versions through 4.1.136.Final disable TLS hostname verification on the SslProvider.OPENSSL client path when a plain (non-extended) X509TrustManager is used and Unsafe-...
CVE-2026-62380
- EPSS 0.32%
- Veröffentlicht 22.08.2026 13:16:39
- Zuletzt bearbeitet 27.08.2026 20:32:22
Netty (io.netty:netty-codec-socks) versions 4.2.0.Final through 4.2.16.Final and 4.1.x through 4.1.136.Final contain null byte, CRLF, and credential injection vulnerabilities in the SOCKS4 (Socks4ClientEncoder) and SOCKS5 (Socks5ClientEncoder) client...
CVE-2026-75595
- EPSS 0.32%
- Veröffentlicht 19.08.2026 21:17:37
- Zuletzt bearbeitet 22.09.2026 19:33:26
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.handler.ssl.SslClientHelloHandler#decode checks the wrong offset before reading the four-byte TLS handshake header, so a ClientHell...
CVE-2026-75596
- EPSS 0.35%
- Veröffentlicht 19.08.2026 20:56:21
- Zuletzt bearbeitet 22.09.2026 19:28:32
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, the default io.netty.handler.ssl.SniHandler constructors use the pre-handshake ClientHello aggregation path in handler/src/main/java/io/net...
CVE-2026-59903
- EPSS 0.4%
- Veröffentlicht 17.08.2026 17:56:28
- Zuletzt bearbeitet 23.09.2026 15:21:27
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.http.cors.CorsHandler setVaryHeader replaces application Vary headers such as Authorization or Cookie with Origin, a...
CVE-2026-59902
- EPSS 0.68%
- Veröffentlicht 17.08.2026 17:48:55
- Zuletzt bearbeitet 23.09.2026 15:31:54
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.sctp.SctpMessageCompletionHandler limits incomplete messages and fragment counts but not maxBufferedBytes, allowing ...