Netty
This hub aggregates every CVE we track for Netty, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
100
CVEs tracked
4
Critical
58
High
1
In CISA KEV
Severity distribution
HIGH58MEDIUM37CRITICAL4LOW1
Monthly trend
0
1
0
0
2
0
0
0
0
0
1
2
1
0
1
0
0
2
0
13
22
19
10
1
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Netty.
- CVE-2026-89044Netty 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final HTTP Request Smuggling via Transfer-Encoding6.5
- CVE-2026-76816Netty: MQTT Topic Name and Client ID Validation Bypass3.5
- CVE-2026-62380Netty before 4.2.16.Final SOCKS Proxy Null Byte Injection7.5
- CVE-2026-62243Netty 4.2.0 through 4.2.16 TLS Hostname Verification Bypass7.5
- CVE-2026-75595Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext9.1
- CVE-2026-75596Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing7.5
- CVE-2026-59903Netty: Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite6.5
- CVE-2026-59902Netty: Memory Exhaustion in SctpMessageCompletionHandler7.5
- CVE-2026-73508Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names5.3
- CVE-2026-73507Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion7.5
- CVE-2026-56818Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state6.5
- CVE-2026-59898Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation7.5
- CVE-2026-59899Netty HttpContentEncoder: Unbounded Per-Connection Queue Growth via HTTP/1.1 Pipelining Leads to Denial of Service7.5
- CVE-2026-59900Netty codec-http2: Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass5.3
- CVE-2026-59901Netty Bzip2Decoder: Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang7.5
Product normalization is registry-driven with AI assist and human review. How it works