Netty

Netty

92 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.26%
  • Veröffentlicht 29.07.2026 17:48:39
  • Zuletzt bearbeitet 06.08.2026 20:29:27

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the `Bzip2Decoder` handler in Netty's compression codec pipeline is vulnerable to a denial-of-service attack through a malformed b...

Exploit
  • EPSS 0.11%
  • Veröffentlicht 29.07.2026 17:37:49
  • Zuletzt bearbeitet 06.08.2026 20:33:28

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Final, Netty's HAProxy encoder ( HAProxyMessageEncoder ) writes AF_UNIX source and destination socket addresses into the HAProxy V1 te...

  • EPSS 0.24%
  • Veröffentlicht 29.07.2026 17:32:46
  • Zuletzt bearbeitet 06.08.2026 20:34:47

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Final, Netty's STOMP encoder ( StompSubframeEncoder ) does not escape or validate header values in  CONNECT  and  CONNECTED  frames, s...

  • EPSS 0.11%
  • Veröffentlicht 28.07.2026 23:17:17
  • Zuletzt bearbeitet 07.08.2026 15:05:31

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator forwards the SslHandshakeCompletionEvent before the asynchronous OCSP validation completes. Thi...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 28.07.2026 23:07:13
  • Zuletzt bearbeitet 07.08.2026 15:05:53

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator flags an out-of-date OCSP response but does not stop processing it, so an expired GOOD response...

  • EPSS 0.47%
  • Veröffentlicht 28.07.2026 22:28:51
  • Zuletzt bearbeitet 07.08.2026 15:05:47

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, HttpPostRequestEncoder constructs multipart HTTP request bodies by directly concatenating user-supplied filenames and field names ...

Exploit
  • EPSS 0.18%
  • Veröffentlicht 21.07.2026 22:26:16
  • Zuletzt bearbeitet 30.07.2026 14:48:49

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final, `OcspClient` does not validate that the `CertificateID` in an OCSP response matches the...

Exploit
  • EPSS 0.52%
  • Veröffentlicht 21.07.2026 22:17:14
  • Zuletzt bearbeitet 07.08.2026 20:47:16

Netty is a network application framework for development of protocol servers and clients. Prior to 4.2.16.Final, Netty's `Http3FrameCodec` buffers incoming data for HTTP/3 reserved frame types up to the wire-specified payload length without limits; `...

  • EPSS 0.38%
  • Veröffentlicht 21.07.2026 22:17:14
  • Zuletzt bearbeitet 30.07.2026 14:47:53

Netty is a network application framework for development of protocol servers and clients. Versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, are vulnerable to security control bypass during the origin evaluation process....

Exploit
  • EPSS 0.37%
  • Veröffentlicht 21.07.2026 22:11:17
  • Zuletzt bearbeitet 30.07.2026 14:46:35

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, a remote unauthenticated peer can leak one direct `ByteBuf` per HTTP/2 `DATA...