CVE-2026-73508
- EPSS 0.33%
- Veröffentlicht 13.08.2026 14:27:20
- Zuletzt bearbeitet 23.09.2026 15:39:29
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.dns.AbstractDnsRecord, io.netty.handler.codec.dns.DefaultDnsRecordDecoder.decodeRecord(), and io.netty.handler.codec...
CVE-2026-73507
- EPSS 0.46%
- Veröffentlicht 13.08.2026 14:25:34
- Zuletzt bearbeitet 23.09.2026 15:40:24
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.xml.XmlFrameDecoder.decode() failed to preserve closing-tag parser state across invocations, so an unauthenticated r...
CVE-2026-56818
- EPSS 0.47%
- Veröffentlicht 07.08.2026 17:14:02
- Zuletzt bearbeitet 23.09.2026 15:56:16
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the RedisArrayAggregator Redis codec clears retained partial aggregate state when the maxNestedArrayDepth limit is exceeded, but it does no...
CVE-2026-59898
- EPSS 0.25%
- Veröffentlicht 29.07.2026 18:02:07
- Zuletzt bearbeitet 06.08.2026 20:35:23
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ab attacker can force WebSocket upgrade via the lax V07 (or V08) handshaker by sending `Sec-WebSocket-Version: 7` and omitting `C...
CVE-2026-59899
- EPSS 0.34%
- Veröffentlicht 29.07.2026 18:00:37
- Zuletzt bearbeitet 06.08.2026 20:25:31
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, `HttpContentEncoder` (the superclass of the production handler `HttpContentCompressor`) maintains a per-channel `ArrayDeque<CharSe...
CVE-2026-59900
- EPSS 0.23%
- Veröffentlicht 29.07.2026 17:58:35
- Zuletzt bearbeitet 06.08.2026 20:29:01
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, Netty's HTTP/2-to-HTTP/1.x translation layer (`Http2StreamFrameToHttpObjectCodec` and `InboundHttp2ToHttpAdapter`) fails to dedupl...
CVE-2026-59901
- EPSS 0.26%
- Veröffentlicht 29.07.2026 17:48:39
- Zuletzt bearbeitet 06.08.2026 20:29:27
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the `Bzip2Decoder` handler in Netty's compression codec pipeline is vulnerable to a denial-of-service attack through a malformed b...
CVE-2026-59919
- EPSS 0.11%
- Veröffentlicht 29.07.2026 17:37:49
- Zuletzt bearbeitet 06.08.2026 20:33:28
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Final, Netty's HAProxy encoder ( HAProxyMessageEncoder ) writes AF_UNIX source and destination socket addresses into the HAProxy V1 te...
CVE-2026-59920
- EPSS 0.24%
- Veröffentlicht 29.07.2026 17:32:46
- Zuletzt bearbeitet 06.08.2026 20:34:47
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Final, Netty's STOMP encoder ( StompSubframeEncoder ) does not escape or validate header values in CONNECT and CONNECTED frames, s...
CVE-2026-56822
- EPSS 0.11%
- Veröffentlicht 28.07.2026 23:17:17
- Zuletzt bearbeitet 07.08.2026 15:05:31
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator forwards the SslHandshakeCompletionEvent before the asynchronous OCSP validation completes. Thi...