Netty

Netty

108 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.44%
  • Veröffentlicht 13.05.2026 18:06:55
  • Zuletzt bearbeitet 10.07.2026 13:44:19

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for...

Exploit
  • EPSS 0.36%
  • Veröffentlicht 13.05.2026 18:04:03
  • Zuletzt bearbeitet 18.05.2026 14:03:25

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.1...

Medienbericht Exploit
  • EPSS 1.01%
  • Veröffentlicht 13.05.2026 18:01:52
  • Zuletzt bearbeitet 18.09.2026 13:18:19

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack...

  • EPSS 0.41%
  • Veröffentlicht 13.05.2026 18:00:28
  • Zuletzt bearbeitet 18.05.2026 14:05:07

Netty is an asynchronous, event-driven network application framework. From 4.2.0.Final to 4.2.13.Final , Netty's epoll transport fails to detect and close TCP connections that receive a RST after being half-closed, leading to stale channels that are ...

Exploit
  • EPSS 1.07%
  • Veröffentlicht 13.05.2026 17:57:43
  • Zuletzt bearbeitet 18.09.2026 13:18:18

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method create...

Exploit
  • EPSS 0.63%
  • Veröffentlicht 13.05.2026 17:54:44
  • Zuletzt bearbeitet 18.09.2026 13:18:20

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 06.05.2026 20:52:47
  • Zuletzt bearbeitet 11.05.2026 14:29:48

Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the star...

Medienbericht
  • EPSS 1.13%
  • Veröffentlicht 27.03.2026 19:55:23
  • Zuletzt bearbeitet 14.09.2026 13:18:18

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. ...

Exploit
  • EPSS 0.64%
  • Veröffentlicht 27.03.2026 19:54:15
  • Zuletzt bearbeitet 14.09.2026 13:18:17

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling atta...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 16.12.2025 00:19:11
  • Zuletzt bearbeitet 02.01.2026 18:50:23

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This...