Netty
This hub aggregates every CVE we track for Netty, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
90
CVEs tracked
3
Critical
53
High
1
In CISA KEV
Severity distribution
HIGH53MEDIUM34CRITICAL3
Monthly trend
0
0
1
0
0
2
0
0
0
0
0
1
2
1
0
1
0
0
2
0
13
22
19
1
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Netty.
- CVE-2026-56818Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state6.5
- CVE-2026-59898Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation7.5
- CVE-2026-59899Netty HttpContentEncoder: Unbounded Per-Connection Queue Growth via HTTP/1.1 Pipelining Leads to Denial of Service7.5
- CVE-2026-59900Netty codec-http2: Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass5.3
- CVE-2026-59901Netty Bzip2Decoder: Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang7.5
- CVE-2026-59919Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address5.5
- CVE-2026-59920Netty: STOMP CONNECT Frame Header Injection6.5
- CVE-2026-56822Netty: TOCTOU in OcspServerCertificateValidator7.4
- CVE-2026-56821Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator7.4
- CVE-2026-59921Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder5.7
- CVE-2026-56820Netty: Missing CertificateID Validation in OCSP Response Allows Replay Attacks7.4
- CVE-2026-56819Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)7.5
- CVE-2026-56817Netty: XML External Entity (XXE) injection via unconfigured XML factory when DTD and entity processing are enabled9.8
- CVE-2026-56816Netty: Memory Exhaustion via HTTP/3 Reserved Frame Types7.5
- CVE-2026-56746Netty has a Security Control Bypass via CORS Short-Circuit Failure6.5
Product normalization is registry-driven with AI assist and human review. How it works