Netty

Netty

108 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.43%
  • Veröffentlicht 26.09.2026 13:23:24
  • Zuletzt bearbeitet 28.09.2026 22:17:30

Rejected reason: This CVE ID has been rejected as a duplicate.

  • EPSS 0.25%
  • Veröffentlicht 26.09.2026 13:23:23
  • Zuletzt bearbeitet 28.09.2026 22:17:30

Rejected reason: This CVE ID has been rejected as a duplicate.

Exploit
  • EPSS 0.25%
  • Veröffentlicht 10.09.2026 17:39:34
  • Zuletzt bearbeitet 18.09.2026 18:17:39

Netty versions 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final fail to properly validate the final transfer coding in the Transfer-Encoding header, allowing attackers to smuggle requests by using malformed encoding declarati...

  • EPSS 0.17%
  • Veröffentlicht 24.08.2026 19:53:12
  • Zuletzt bearbeitet 09.09.2026 21:06:39

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.137.Final and 4.2.17.Final, MqttEncoder does not validate client identifiers, will topics, usernames, and PUBLISH topic names before encoding, allowing prohib...

  • EPSS 0.16%
  • Veröffentlicht 22.08.2026 13:16:39
  • Zuletzt bearbeitet 10.09.2026 20:46:19

Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final and versions through 4.1.136.Final disable TLS hostname verification on the SslProvider.OPENSSL client path when a plain (non-extended) X509TrustManager is used and Unsafe-...

  • EPSS 0.32%
  • Veröffentlicht 22.08.2026 13:16:39
  • Zuletzt bearbeitet 27.08.2026 20:32:22

Netty (io.netty:netty-codec-socks) versions 4.2.0.Final through 4.2.16.Final and 4.1.x through 4.1.136.Final contain null byte, CRLF, and credential injection vulnerabilities in the SOCKS4 (Socks4ClientEncoder) and SOCKS5 (Socks5ClientEncoder) client...

  • EPSS 0.32%
  • Veröffentlicht 19.08.2026 21:17:37
  • Zuletzt bearbeitet 22.09.2026 19:33:26

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.handler.ssl.SslClientHelloHandler#decode checks the wrong offset before reading the four-byte TLS handshake header, so a ClientHell...

  • EPSS 0.35%
  • Veröffentlicht 19.08.2026 20:56:21
  • Zuletzt bearbeitet 22.09.2026 19:28:32

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, the default io.netty.handler.ssl.SniHandler constructors use the pre-handshake ClientHello aggregation path in handler/src/main/java/io/net...

  • EPSS 0.4%
  • Veröffentlicht 17.08.2026 17:56:28
  • Zuletzt bearbeitet 23.09.2026 15:21:27

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.http.cors.CorsHandler setVaryHeader replaces application Vary headers such as Authorization or Cookie with Origin, a...

  • EPSS 0.68%
  • Veröffentlicht 17.08.2026 17:48:55
  • Zuletzt bearbeitet 23.09.2026 15:31:54

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.sctp.SctpMessageCompletionHandler limits incomplete messages and fragment counts but not maxBufferedBytes, allowing ...