CVE-2026-41417
- EPSS 0.31%
- Veröffentlicht 06.05.2026 20:52:47
- Zuletzt bearbeitet 11.05.2026 14:29:48
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the star...
CVE-2026-33871
- EPSS 1.13%
- Veröffentlicht 27.03.2026 19:55:23
- Zuletzt bearbeitet 18.08.2026 12:18:25
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. ...
CVE-2026-33870
- EPSS 0.64%
- Veröffentlicht 27.03.2026 19:54:15
- Zuletzt bearbeitet 04.08.2026 13:18:20
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling atta...
CVE-2025-67735
- EPSS 0.33%
- Veröffentlicht 16.12.2025 00:19:11
- Zuletzt bearbeitet 02.01.2026 18:50:23
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This...
CVE-2025-59419
- EPSS 1.59%
- Veröffentlicht 15.10.2025 15:42:30
- Zuletzt bearbeitet 15.04.2026 00:35:42
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.128.Final and 4.2.7.Final, the SMTP codec in Netty contains an SMTP command injection vulnerability due to insufficient input validation for Carriage Retur...
CVE-2025-58057
- EPSS 0.6%
- Veröffentlicht 03.09.2025 21:46:49
- Zuletzt bearbeitet 08.09.2025 16:45:55
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In netty-codec-compression versions 4.1.124.Final and below, and netty-codec versions 4.2.4.Final a...
CVE-2025-58056
- EPSS 0.68%
- Veröffentlicht 03.09.2025 20:56:50
- Zuletzt bearbeitet 08.09.2025 16:46:36
Netty is an asynchronous event-driven network application framework for development of maintainable high performance protocol servers and clients. In versions 4.1.124.Final, and 4.2.0.Alpha3 through 4.2.4.Final, Netty incorrectly accepts standalone n...
CVE-2025-55163
- EPSS 1.05%
- Veröffentlicht 13.08.2025 14:17:36
- Zuletzt bearbeitet 04.11.2025 22:16:30
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.124.Final and 4.2.4.Final, Netty is vulnerable to MadeYouReset DDoS. This is a logical vulnerability in the HTTP/2 protocol, that uses malformed HTTP/2 contro...
CVE-2025-25193
- EPSS 0.38%
- Veröffentlicht 10.02.2025 22:15:38
- Zuletzt bearbeitet 11.06.2025 15:36:22
Netty, an asynchronous, event-driven network application framework, has a vulnerability in versions up to and including 4.1.118.Final. An unsafe reading of environment file could potentially cause a denial of service in Netty. When loaded on an Windo...
CVE-2025-24970
- EPSS 2.15%
- Veröffentlicht 10.02.2025 22:15:38
- Zuletzt bearbeitet 05.09.2025 17:20:12
Netty, an asynchronous, event-driven network application framework, has a vulnerability starting in version 4.1.91.Final and prior to version 4.1.118.Final. When a special crafted packet is received via SslHandler it doesn't correctly handle validati...