netty
OSS Librariesoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting netty.
- CVE-2026-54251netty-incubator-codec-ohttp: [OHttpServerCodec] Native Direct-Memory Leak on AEAD Decryption Failure Leads to Gateway Denial of Service
- CVE-2026-89044Netty 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final HTTP Request Smuggling via Transfer-Encoding6.5
- CVE-2026-76816Netty: MQTT Topic Name and Client ID Validation Bypass3.5
- CVE-2026-62380Netty before 4.2.16.Final SOCKS Proxy Null Byte Injection7.5
- CVE-2026-62243Netty 4.2.0 through 4.2.16 TLS Hostname Verification Bypass7.5
- CVE-2026-75595Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext9.1
- CVE-2026-75596Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing7.5
- CVE-2026-59903Netty: Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite6.5
- CVE-2026-59902Netty: Memory Exhaustion in SctpMessageCompletionHandler7.5
- CVE-2026-73508Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names5.3
- CVE-2026-73507Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion7.5
- CVE-2026-56818Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state6.5
- CVE-2026-59898Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation7.5
- CVE-2026-59899Netty HttpContentEncoder: Unbounded Per-Connection Queue Growth via HTTP/1.1 Pipelining Leads to Denial of Service7.5
- CVE-2026-59900Netty codec-http2: Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass5.3