CVE-2026-56821
- EPSS 0.14%
- Veröffentlicht 28.07.2026 23:07:13
- Zuletzt bearbeitet 07.08.2026 15:05:53
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator flags an out-of-date OCSP response but does not stop processing it, so an expired GOOD response...
CVE-2026-59921
- EPSS 0.47%
- Veröffentlicht 28.07.2026 22:28:51
- Zuletzt bearbeitet 07.08.2026 15:05:47
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, HttpPostRequestEncoder constructs multipart HTTP request bodies by directly concatenating user-supplied filenames and field names ...
CVE-2026-56820
- EPSS 0.18%
- Veröffentlicht 21.07.2026 22:26:16
- Zuletzt bearbeitet 30.07.2026 14:48:49
Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final, `OcspClient` does not validate that the `CertificateID` in an OCSP response matches the...
CVE-2026-56746
- EPSS 0.38%
- Veröffentlicht 21.07.2026 22:17:14
- Zuletzt bearbeitet 30.07.2026 14:47:53
Netty is a network application framework for development of protocol servers and clients. Versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, are vulnerable to security control bypass during the origin evaluation process....
CVE-2026-56816
- EPSS 0.52%
- Veröffentlicht 21.07.2026 22:17:14
- Zuletzt bearbeitet 07.08.2026 20:47:16
Netty is a network application framework for development of protocol servers and clients. Prior to 4.2.16.Final, Netty's `Http3FrameCodec` buffers incoming data for HTTP/3 reserved frame types up to the wire-specified payload length without limits; `...
CVE-2026-56819
- EPSS 0.37%
- Veröffentlicht 21.07.2026 22:11:17
- Zuletzt bearbeitet 30.07.2026 14:46:35
Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, a remote unauthenticated peer can leak one direct `ByteBuf` per HTTP/2 `DATA...
CVE-2026-56817
- EPSS 0.37%
- Veröffentlicht 21.07.2026 22:06:56
- Zuletzt bearbeitet 30.07.2026 14:48:18
Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, any caller that can deliver bytes to a Netty channel pipeline containing `Xm...
CVE-2026-56745
- EPSS 0.61%
- Veröffentlicht 21.07.2026 21:31:25
- Zuletzt bearbeitet 30.07.2026 14:46:55
Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, the `SpdyHttpDecoder` handler in Netty's SPDY-to-HTTP codec allocates a pool...
CVE-2026-55851
- EPSS 0.61%
- Veröffentlicht 21.07.2026 21:22:34
- Zuletzt bearbeitet 30.07.2026 14:48:31
Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final up to (but not including) 4.2.16.Final, and 4.1.0.Final up to (but not including) 4.1.135, the `HAProxyMessageDecoder` in Netty's `codec...
CVE-2026-55833
- EPSS 0.42%
- Veröffentlicht 20.07.2026 23:18:07
- Zuletzt bearbeitet 23.07.2026 13:34:45
Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has exceeded `...