PatchSiren

Netty CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM netty CVE published 2026-09-26

CVE-2026-100666

Netty's HttpServerCodec in versions 4.2.0.Final through 4.2.16.Final and 4.1.136.Final is vulnerable to response desynchronization. This issue arises when a client pipelines an HTTP/1.1 GET request with an Expect: 100-continue header followed by a HEAD request. The 100 Continue response consumes the queued GET method, causing the subsequent 200 OK for the GET to be paired with the HEAD request and its bod [truncated]

HIGH netty CVE published 2026-09-26

CVE-2026-100665

CVE-2026-100665 is a high-severity vulnerability in Netty versions from 4.2.11.Final before 4.2.18.Final. The issue lies in the incomplete hostname verification fix in the QUIC certificate verification path when using a plain X509TrustManager. This allows attackers on the network path to bypass hostname authentication for QUIC clients by presenting a certificate chain for the wrong hostname.

HIGH netty CVE published 2026-09-26

CVE-2026-100663

Netty's HTTP/3 codec vulnerability allows for malformed HTTP/3 CONNECT requests, potentially bypassing tunnel allow-lists, egress policy, backend selection, or audit controls in Netty-based HTTP/1-to-HTTP/3 proxies or gateways. The issue is fixed in 4.2.18.Final. A remote client can send a CONNECT request whose Host header names a different authority than the request-target, producing a malformed HTTP/3 C [truncated]

HIGH netty CVE published 2026-09-26

CVE-2026-100662

Netty's HTTP/3 codec versions 4.2.0.Final through 4.2.17.Final contain an uncontrolled resource consumption vulnerability. A remote, unauthenticated peer can declare a very large literal length and cause the ByteToMessageDecoder MERGE cumulator to retain and grow the per-connection buffer, ultimately triggering a large byte-array allocation. This leads to unbounded per-connection heap growth and OutOfMemo [truncated]

HIGH netty CVE published 2026-09-26

CVE-2026-100661

A denial-of-service vulnerability exists in Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final. This issue arises from the QPACK prefixed-integer decoder (QpackUtil.decodePrefixedInteger) not bounding the number of continuation bytes it processes. A remote, unauthenticated peer can exploit this by opening a QPACK unidirectional stream and sending a specially crafte [truncated]

HIGH netty CVE published 2026-09-26

CVE-2026-100660

CVE-2026-100660 is a high-severity vulnerability in Netty's HTTP/3 codec that can lead to denial of service via unbounded heap growth. A remote, unauthenticated HTTP/3 client can exploit this by omitting Section Acknowledgments while issuing sequential requests over a single QUIC connection, bypassing concurrent-stream limits. The issue is fixed in version 4.2.18.Final.

MEDIUM netty CVE published 2026-09-26

CVE-2026-100659

CVE-2026-100659 is a vulnerability in Netty's HTTP/3 codec (io.netty:netty-codec-http3) in versions 4.2.0.Final through 4.2.17.Final. The issue allows a remote unauthenticated peer to send a single HEADERS frame with conflicting :authority and host header fields, potentially bypassing routing, virtual-host, and access-control decisions. This issue is fixed in 4.2.18.Final.

MEDIUM netty CVE published 2026-09-26

CVE-2026-100658

CVE-2026-100658 is a medium-severity vulnerability in Netty's WebSocketServerExtensionHandler, which can lead to a denial-of-service (DoS) attack. The handler has an unbounded per-connection queue that can grow without limit, causing the JVM to exhaust heap memory and terminate with OutOfMemoryError. This issue affects Netty versions 4.1.88.Final through 4.1.137.Final and 4.2.0.Final through 4.2.17.Final, [truncated]

HIGH netty CVE published 2026-09-26

CVE-2026-100657

A remote peer can cause a ByteBuf leak in Netty's STOMP codec by sending a complete, well-formed frame body and withholding its terminating NUL byte, potentially leading to memory exhaustion. This issue affects versions up to and including 4.1.137.Final and versions 4.2.0.Final through 4.2.17.Final. The vulnerability is fixed in 4.1.138.Final and 4.2.18.Final. Defenders should assess exposure and prioriti [truncated]

HIGH netty CVE published 2026-09-26

CVE-2026-100656

CVE-2026-100656 is a high-severity vulnerability in Netty's HttpServerCodec, allowing for unbounded heap growth and denial of service via pipelined HTTP/1.1 requests. Affected versions include 4.2.0.Final through 4.2.17.Final and all releases up to 4.1.137.Final. The issue is fixed in 4.2.18.Final and 4.1.138.Final. This vulnerability can be exploited by a remote, unauthenticated attacker who pipelines HT [truncated]

MEDIUM netty CVE published 2026-09-26

CVE-2026-100655

CVE-2026-100655 is a denial-of-service vulnerability affecting Netty versions up to and including 4.1.137.Final and from 4.2.0.Final through 4.2.17.Final. The vulnerability is caused by the SpdySessionHandler accepting an unlimited number of concurrent remote-initiated SPDY streams, which can lead to a JVM OutOfMemoryError and crash the service. This issue arises because SpdySessionHandler defaults localC [truncated]

MEDIUM netty CVE published 2026-09-10

CVE-2026-89044

Netty versions 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final are vulnerable to HTTP request smuggling attacks due to improper validation of the final transfer coding in the Transfer-Encoding header. Attackers can exploit this by using malformed encoding declarations, such as splitting Transfer-Encoding headers across multiple lines or using values like 'chunked, xchunked' to by [truncated]

LOW netty CVE published 2026-08-24

CVE-2026-76816

CVE-2026-76816 is a vulnerability in Netty's MQTT encoder that allows prohibited null bytes in MQTT UTF-8 string fields, potentially causing routing, access-control, or identity mismatches in downstream brokers. The issue is fixed in Netty versions 4.1.137.Final and 4.2.17.Final. Affected product deployments should be reviewed for exposure, and owners should verify input validation. This vulnerability has [truncated]

HIGH netty CVE published 2026-08-22

CVE-2026-62243

CVE-2026-62243 debrief based on the supplied source corpus. The vulnerability affects Netty versions 4.2.0.Final through 4.2.16.Final and 4.1.136.Final, allowing for TLS hostname verification bypass due to the use of a plain X509TrustManager with OpenSSL client. This could enable man-in-the-middle attacks. Defenders should assess exposure and prioritize remediation, especially in configurations using Open [truncated]

HIGH netty CVE published 2026-08-19

CVE-2026-75596

CVE-2026-75596 is a high-severity vulnerability in the Netty framework, affecting its handling of TLS handshakes. An unauthenticated remote peer can exploit this by advertising a large ClientHello and delivering its body in thousands of tiny records, causing quadratic CPU work on the event loop. This degrades TLS handling for other clients and can lead to denial-of-service attacks. The issue is fixed in N [truncated]

CRITICAL netty CVE published 2026-08-19

CVE-2026-75595

CVE-2026-75595 is a critical vulnerability in the Netty framework that allows an unauthenticated remote attacker to bypass mutual TLS requirements under certain conditions. The issue arises from the incorrect handling of TLS handshake headers in the SslClientHelloHandler class, which can lead to the selection of a default SslContext with less stringent authentication requirements. This vulnerability affec [truncated]

MEDIUM netty CVE published 2026-08-17

CVE-2026-59903

CVE-2026-59903 debrief based on the supplied source corpus. The vulnerability in Netty's io.netty.handler.codec.http.cors.CorsHandler allows a caching proxy or CDN to reuse authenticated responses across users and disclose sensitive information. This issue is fixed in Netty versions 4.1.137.Final and 4.2.17.Final. Defenders should assess exposure and verify patches for affected Netty deployments, particul [truncated]

HIGH netty CVE published 2026-08-17

CVE-2026-59902

CVE-2026-59902 is a high-severity vulnerability in the Netty network application framework that can lead to memory exhaustion via large SCTP fragments. The issue is fixed in Netty versions 4.1.137.Final and 4.2.17.Final. Defenders should assess exposure, prioritize upgrades, and monitor for large SCTP fragments to mitigate potential impacts. This vulnerability affects systems using Netty for network commu [truncated]

MEDIUM netty CVE published 2026-08-13

CVE-2026-73508

CVE-2026-73508 is a vulnerability in the Netty framework that could lead to a denial-of-service (DoS) condition. The issue arises from the improper handling of malformed domain names in DNS packets, which can cause a memory leak. This CVE was published on 2026-08-13T15:20:17.463Z and was last modified on 2026-09-09T20:58:37.713Z. Affected systems using Netty for DNS operations should be assessed for expos [truncated]

MEDIUM netty CVE published 2026-08-07

CVE-2026-56818

CVE-2026-56818 is a vulnerability in the Netty framework that allows an unauthenticated peer to retain attacker-controlled aggregate state across a security-limit exception. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final. The vulnerability occurs in the RedisArrayAggregator Redis codec, which clears retained partial aggregate state when the maxNestedArrayDepth limit is exceeded, but not wh [truncated]

MEDIUM netty CVE published 2026-07-29

CVE-2026-59898

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-29T19:16:48.740Z and has not been modified since then. The NVD entry is currently Analyzed. The vulnerability in Netty allows an attacker to force a WebSocket upgrade via the lax V07 handshaker, enabling HTTP request smuggling and protocol-confusion attacks. This issue was fixed in Netty versions 4. [truncated]

MEDIUM netty CVE published 2026-07-29

CVE-2026-59920

Netty is an asynchronous, event-driven network application framework. A vulnerability in Netty's STOMP encoder (StompSubframeEncoder) allows an attacker to inject additional STOMP headers by not escaping or validating header values in CONNECT and CONNECTED frames. This issue affects Netty versions prior to 4.1.136.Final and 4.2.16.Final, with a CVSS score of 6.5 and MEDIUM severity. The vulnerability can [truncated]

HIGH netty CVE published 2026-07-29

CVE-2026-59901

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-29T18:16:56.467Z and has not been modified since then. This CVE-2026-59901 vulnerability affects Netty, an asynchronous, event-driven network application framework. The vulnerability class is a denial-of-service (DoS) attack through a malformed bzip2 stream that permanently captures the event-loop t [truncated]

MEDIUM netty CVE published 2026-07-29

CVE-2026-59900

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-29T18:16:56.320Z and has not been modified since then. Netty's HTTP/2-to-HTTP/1.x translation layer fails to deduplicate or validate 'Host' headers when an HTTP/2 client supplies both the ':authority' pseudo-header and a literal 'host' header in a single HEADERS frame. The translator maps ':authorit [truncated]

HIGH netty CVE published 2026-07-29

CVE-2026-56822

The CVE-2026-56822 vulnerability affects Netty, an asynchronous, event-driven network application framework. This vulnerability allows sensitive application data to be leaked to a revoked server before the channel is closed by the OCSP check. Users of Netty versions prior to 4.1.136.Final and 4.2.16.Final are affected. The vulnerability is caused by the OcspServerCertificateValidator forwarding the SslHan [truncated]

HIGH netty CVE published 2026-07-29

CVE-2026-56821

Netty, an asynchronous event-driven network application framework, has a vulnerability in its OcspServerCertificateValidator. This validator flags out-of-date OCSP responses but does not stop processing them, potentially allowing an on-path attacker to bypass certificate revocation via replay of an expired GOOD response. The affected versions are prior to 4.1.136.Final and 4.2.16.Final. Teams using these [truncated]

MEDIUM netty CVE published 2026-07-28

CVE-2026-59921

CVE-2026-59921 is a vulnerability in Netty's HttpPostRequestEncoder, allowing for arbitrary MIME header injection due to unsanitized CRLF characters in user-supplied filenames and field names. This issue is fixed in Netty versions 4.1.136.Final and 4.2.16.Final. Affected users should verify their Netty versions and apply updates if necessary. The CVE record was published on 2026-07-28T23:17:09.923Z and ha [truncated]

HIGH netty CVE published 2026-07-21

CVE-2026-56820

CVE-2026-56820 is a high-severity vulnerability in Netty, a network application framework, that allows for replay attacks due to improper OCSP response validation. The issue affects Netty versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final. The vulnerability is caused by the `OcspClient` not validating that the `CertificateID` in an OCSP response matches the requested `CertificateID`, whi [truncated]

HIGH netty CVE published 2026-07-21

CVE-2026-56819

CVE-2026-56819 is a high-severity vulnerability affecting Netty, a network application framework used for developing protocol servers and clients. The issue, rated with a CVSS score of 7.5, allows a remote unauthenticated peer to cause memory exhaustion by leaking one direct ByteBuf per HTTP/2 DATA frame in applications that enable HTTP/2 content decompression via DelegatingDecompressorFrameListener. This [truncated]

HIGH netty CVE published 2026-07-21

CVE-2026-56817

CVE-2026-56817 is a high-severity vulnerability in Netty, a network application framework. The issue allows for conditional XML external entity risk due to DTD and entity handling being active in certain configurations. This vulnerability affects Netty versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final. It was fixed in versions 4.1.136.Final and 4.2.16.Final.