These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-56816 is a high-severity denial of service vulnerability in Netty's Http3FrameCodec. The issue arises from the codec's ability to buffer incoming data for HTTP/3 reserved frame types up to the wire-specified payload length without limits. This allows an attacker to open multiple QUIC streams and send reserved frames with very large payload lengths, potentially causing memory exhaustion. The vulne [truncated]
CVE-2026-56746 is a security control bypass vulnerability in Netty, a network application framework. The issue affects versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final. The vulnerability occurs in the CorsHandler's origin evaluation process, allowing an attacker to bypass security controls by sending a request with an Origin: null header. This bypasses the short-circuit mech [truncated]
CVE-2026-56745 is a high-severity vulnerability affecting Netty, a network application framework used for developing protocol servers and clients. The vulnerability exists in versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final. The issue arises in the `SpdyHttpDecoder` handler of Netty's SPDY-to-HTTP codec. When processing a client-initiated `SYN_STREAM` frame with `FLAG_FIN=0` [truncated]
CVE-2026-55851 is a denial-of-service vulnerability in Netty's HAProxyMessageDecoder. The issue arises from improper protocol version detection, leading to an unbounded cumulation buffer that can exhaust direct memory. This vulnerability affects Netty versions 4.2.0.Final up to (but not including) 4.2.16.Final, and 4.1.0.Final up to (but not including) 4.1.135. The issue is fixed in versions 4.1.136.Final [truncated]
CVE-2026-55833 is a high-severity vulnerability in Netty, a network application framework. The issue affects versions prior to 4.1.136.Final and 4.2.16.Final. Netty's SPDY header decoding process continues to inflate zlib-compressed header blocks even after the raw header parser has exceeded the `maxHeaderSize` limit and marked the frame as truncated in `SpdyFrameCodec`. This allows a remote peer to send [truncated]
Netty is vulnerable to a denial-of-service (DoS) attack due to improper handling of SPDY SETTINGS frames. A remote attacker can send a specially crafted SETTINGS frame to cause excessive heap growth and ordered-map insertion work, leading to a potential DoS. This issue affects Netty versions prior to 4.1.136.Final and 4.2.16.Final, and users should be aware of this vulnerability and take steps to mitigate it.
CVE-2026-44891 is a denial of service vulnerability in Netty's StompSubframeDecoder. The issue is fixed in Netty versions 4.1.136.Final and 4.2.16.Final. This vulnerability allows an attacker to send a large number of short headers that accumulate in memory, causing an OutOfMemoryError and denial of service for servers exposing a STOMP endpoint based on StompSubframeDecoder. Users of affected versions sho [truncated]
CVE-2026-50560 is a vulnerability in Netty, a network application framework. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's HTTP/2 max header size handling produces an attack similar to HTTP/2 Rapid Reset. The vulnerability is caused by the `SETTINGS_MAX_HEADER_LIST_SIZE` setting in the http2 specification. When a client sends this setting to Netty, it can cause Netty to behave in a way that is [truncated]
CVE-2026-50020 is a vulnerability in Netty's HttpObjectDecoder. Prior to versions 4.1.135.Final and 4.2.15.Final, the decoder skips certain bytes, including non-CRLF control characters, which can lead to request-boundary confusion in pipelined or multiplexed transports. This vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity.
Netty is vulnerable to a high-severity issue where a small malicious RedisArrayAggregator header can claim a huge initial capacity, potentially leading to resource exhaustion. This affects versions prior to 4.1.135.Final and 4.2.15.Final. The CVE record was published on 2026-06-12T16:16:31.313Z and has not been modified since then. The NVD entry is currently Modified.
CVE-2026-50010 is a vulnerability in Netty, a network application framework, that can lead to a lack of hostname verification in certain configurations. This issue arises from the way Netty handles trust managers, specifically when using `SimpleTrustManagerFactory.engineGetTrustManagers()` and related paths. These paths wrap any user-supplied plain `X509TrustManager` in `X509TrustManagerWrapper`, which ex [truncated]
CVE-2026-50009 is a vulnerability in Netty, a network application framework. Prior to version 4.2.15.Final, Netty QUIC exposes the stateless reset token on the network path when using the default HMAC-based connection-ID and stateless-reset-token generators. This allows an on-path attacker to derive the reset token for the server's current source connection ID from bytes that appear as the connection ID i [truncated]
CVE-2026-48748 is a high-severity vulnerability in the Netty HTTP/3 codec that allows for memory exhaustion via the creation of an infinite number of blocked streams, potentially leading to an Out-of-Memory (OOM) error. This issue was patched in Netty version 4.2.15.Final.
A memory leak vulnerability exists in the HAProxy PROXY protocol v2 codec in Netty, a network application framework. The issue occurs when a client sends a syntactically valid header containing nested `PP2_TYPE_SSL` TLVs at depth two or greater. This leak happens on the successful parse path, with no exception thrown, and the message fires downstream. The decoder removes itself, and the application releas [truncated]
A resource leak vulnerability exists in the Netty network application framework, specifically in the `DelegatingDecompressorFrameListener` class. This class is responsible for orchestrating HTTP/2 decompression. A remote peer could send frames that would result in the flow-controller throwing, potentially leading to a resource leak that might cause the JVM to crash due to an OutOfMemoryError (OOME). The i [truncated]
Netty is vulnerable to a denial-of-service (DoS) attack due to a memory leak in the RedisArrayAggregator handler. This handler permanently leaks pooled direct-memory buffers when a Redis pipeline connection closes before a RESP array aggregate completes. The issue affects Netty versions before 4.1.135.Final and 4.2.15.Final. The vulnerability can lead to DoS attacks due to memory leaks, and repeated conne [truncated]
Netty, a network application framework, is vulnerable to DNS cache poisoning due to insufficient validation of NS record bailiwick in `DnsResolveContext`. This allows an attacker controlling an authoritative name server for a subdomain to poison the cache for parent domains. The issue is patched in Netty versions 4.1.135.Final and 4.2.15.Final. Defenders should assess exposure and apply patches to prevent [truncated]
CVE-2026-47244 is a vulnerability in Netty's HTTP/2 server implementation. Prior to versions 4.1.135.Final and 4.2.15.Final, the server could allocate excessive stream objects, potentially leading to resource exhaustion and amplification attacks. The issue arises from the DefaultHttp2Connection.DefaultEndpoint initializing maxActiveStreams/maxStreams to Integer.MAX_VALUE and Http2Settings not inserting SE [truncated]
A vulnerability in Netty's netty-transport-sctp component can lead to a denial-of-service (DoS) attack. The issue arises from the improper handling of SctpMessage fragments, which can cause the accumulator to grow indefinitely, leading to increased memory usage and potential performance degradation. This vulnerability can be exploited by an attacker to launch a DoS attack, potentially causing system crash [truncated]
Netty is vulnerable to a DNS response validation issue. The DnsResolveContext in Netty fails to validate the origin (bailiwick) of CNAME records in DNS responses. This issue was patched in Netty versions 4.1.135.Final and 4.2.15.Final. The vulnerability allows for potential DNS response attacks. Defenders should verify exposure, apply patches, and review DNS response validation. Affected systems should be [truncated]
CVE-2026-45673 is a DNS Cache Poisoning vulnerability in Netty, a network application framework. The vulnerability has a CVSS score of 6.8 and was published on 2026-06-12T15:16:27.417Z. The vulnerability exists in Netty's DNS resolver, which uses a predictable PRNG for generating DNS transaction IDs and defaults to a static UDP source port. This combination reduces the entropy of DNS queries, enabling DNS [truncated]
CVE-2026-45536 is a MEDIUM severity vulnerability in Netty, a network application framework. The vulnerability occurs in the netty_unix_socket_recvFd function, where a peer-sent SCM_RIGHTS cmsg carrying two ints can cause a file descriptor leak. This happens when the application opts into DomainSocketReadMode.FILE_DESCRIPTORS (non-default) via Epoll/KQueue DomainSocketChannel. The issue is patched in vers [truncated]
CVE-2026-45416 is a high-severity vulnerability in the Netty network application framework that could allow for denial-of-service (DoS) attacks. The issue arises from the SslClientHelloHandler.decode() method, which can lead to a huge/unpooled allocation when handling large ClientHello requests. This vulnerability affects Netty versions prior to 4.1.135.Final and 4.2.15.Final.
CVE-2026-44894 is a vulnerability in Netty's NoQuicTokenHandler. Prior to version 4.2.15.Final, it incorrectly validates tokens, allowing an attacker to bypass the 3× anti-amplification send limit. This could lead to a high-impact attack, with a CVSS score of 7.5.
Netty is vulnerable to an issue in netty-codec-haproxy where a specially crafted PP2_TYPE_SSL TLV can cause an IndexOutOfBoundsException. This exception is thrown because HAProxyMessage.readNextTLV() reads a TLV length that is below 5, leading to an issue when reading the 1-byte client field and 4-byte verify field. The exception propagates as the HAProxyMessageDecoder only catches HAProxyProtocolExceptio [truncated]
CVE-2026-44892 is a HIGH severity vulnerability in the Netty network application framework. The `Http3ConnectionHandler` in the Netty HTTP/3 codec has a default configuration that lacks an enforced maximum header size limit. When a peer does not specify `HTTP3_SETTINGS_MAX_FIELD_SECTION_SIZE`, the implementation defaults to an unbounded limit. This allows a malicious client or server to send an enormous n [truncated]
Netty is vulnerable to a denial-of-service (DoS) attack when processing crafted Redis payloads. This issue affects netty-codec-redis in versions before 4.1.135.Final and 4.2.15.Final. An attacker can exploit this by sending malicious payloads across multiple connections, leading to an OutOfDirectMemoryError that prevents legitimate connections from being processed. The vulnerability is patched in versions [truncated]
Netty is vulnerable to a denial-of-service (DoS) attack due to an issue in the netty-codec-redis component. An attacker can cause a DoS by sending a crafted Redis payload with deeply nested arrays, leading to memory exhaustion and an OutOfMemoryError. The issue is patched in versions 4.1.135.Final and 4.2.15.Final. This vulnerability affects users of Netty's netty-codec-redis component, particularly those [truncated]
Netty is vulnerable to an issue in IpSubnetFilterRule.compareTo() that allows an attacker to bypass IPv6 subnet rules. This issue affects Netty versions prior to 4.1.135.Final and 4.2.15.Final. The vulnerability has been patched in versions 4.1.135.Final and 4.2.15.Final. Defenders should review network configurations and prioritize patching to prevent potential unauthorized access. The issue is particula [truncated]
CVE-2026-48480 is a MEDIUM severity vulnerability in the Netty Incubator Codec OHTTP, a Java language binary HTTP parser. Prior to version 0.0.22.Final, the codec-ohttp implementation of draft-ietf-ohai-chunked-ohttp does not verify that a cryptographically-signed final chunk was received before the outer HTTP body terminates. This allows an on-path adversary (the OHTTP relay itself, or any MITM on the re [truncated]