- EPSS 0.14%
- Veröffentlicht 12.06.2026 14:12:48
- Zuletzt bearbeitet 15.06.2026 02:14:53
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, netty_unix_socket_recvFd sets msg_control to `char control[CMSG_SPACE(sizeof(int))]` (line 940) — 24 bytes on ...
CVE-2026-45416
- EPSS 0.86%
- Veröffentlicht 12.06.2026 14:10:05
- Zuletzt bearbeitet 20.08.2026 13:18:49
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SslClientHelloHandler.decode() reads the 24-bit TLS handshake length and, when the ClientHello does not fit in...
CVE-2026-44894
- EPSS 0.14%
- Veröffentlicht 12.06.2026 14:06:54
- Zuletzt bearbeitet 15.07.2026 02:22:01
Netty is a network application framework for development of protocol servers and clients. NoQuicTokenHandler is the tokenHandler used when the application does not set one. Prior to version 4.2.15.Final, its writeToken() returns false (server will no...
CVE-2026-44893
- EPSS 0.62%
- Veröffentlicht 12.06.2026 14:00:25
- Zuletzt bearbeitet 13.08.2026 13:19:04
Netty is a network application framework for development of protocol servers and clients. In netty-codec-haproxy prior to versions 4.1.135.Final and 4.2.15.Final, when decoding a PP2_TYPE_SSL TLV, HAProxyMessage.readNextTLV() first calls `header.reta...
CVE-2026-44892
- EPSS 0.28%
- Veröffentlicht 12.06.2026 05:16:32
- Zuletzt bearbeitet 15.06.2026 02:30:19
Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final, the default configuration of the `Http3ConnectionHandler` in the Netty HTTP/3 codec lacks an enforced maximum header size limit. ...
CVE-2026-44890
- EPSS 0.46%
- Veröffentlicht 11.06.2026 20:52:50
- Zuletzt bearbeitet 12.08.2026 12:19:27
Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can cause DoS by sending crafted Redis payloads across multiple connections w...
CVE-2026-44250
- EPSS 0.46%
- Veröffentlicht 11.06.2026 20:49:00
- Zuletzt bearbeitet 12.08.2026 12:19:21
Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can cause DoS by sending a crafted Redis payload with deeply nested arrays. T...
CVE-2026-44249
- EPSS 1.03%
- Veröffentlicht 11.06.2026 20:46:14
- Zuletzt bearbeitet 20.08.2026 13:18:38
Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFil...
CVE-2026-44248
- EPSS 0.49%
- Veröffentlicht 13.05.2026 18:23:37
- Zuletzt bearbeitet 03.08.2026 13:18:32
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the dec...
CVE-2026-42587
- EPSS 0.99%
- Veröffentlicht 13.05.2026 18:22:21
- Zuletzt bearbeitet 13.08.2026 13:18:57
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This l...