PatchSiren

Netty CVE debriefs · Page 3

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Netty CVE published 2026-06-04

CVE-2026-48040

CVE-2026-48040 is a vulnerability in the Netty incubator codec.bhttp, a Java language binary HTTP parser. The library implements Oblivious HTTP (RFC 9458) using BoringSSL's HPKE C library via JNI. When deriving native memory addresses for cryptographic operations, versions prior to 0.0.22.Final provide a fallback path for direct ByteBufs that do not expose their memory address through `hasMemoryAddress()` [truncated]

MEDIUM Netty CVE published 2026-06-04

CVE-2026-41207

The Netty-Incubator-Codec-Ohttp, a Java language binary HTTP parser, has a vulnerability in its HKDF (Keyed-Hash Message Authentication Code) key material generation. Prior to version 0.0.21.Final, the HKDF_expand function returns a non-NULL value on failure, which is a byte array filled with zeros. This makes it impossible to distinguish between a successful and failed operation. The output of this funct [truncated]

MEDIUM Netty CVE published 2026-05-13

CVE-2026-44248

CVE-2026-44248 is a medium-severity uncontrolled resource consumption vulnerability in Netty's MQTT 5 decoder. The flaw exists because the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method executes before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check, allowing decodeProperties [truncated]

HIGH Netty CVE published 2026-05-13

CVE-2026-42587

Netty's HttpContentDecompressor and DelegatingDecompressorFrameListener fail to enforce the maxAllocation decompression limit for Brotli (br), zstd, and snappy encodings, allowing attackers to bypass memory protections by using alternative Content-Encoding headers. This enables unbounded memory allocation leading to out-of-memory denial of service. The vulnerability affects Netty versions prior to 4.1.133 [truncated]

MEDIUM Netty CVE published 2026-05-13

CVE-2026-42585

Netty versions prior to 4.1.133.Final and 4.2.13.Final contain an HTTP request smuggling vulnerability stemming from incorrect parsing of malformed Transfer-Encoding headers. The flaw allows attackers to manipulate how front-end and back-end servers interpret HTTP request boundaries, potentially enabling unauthorized access to internal systems, cache poisoning, or credential hijacking. The vulnerability c [truncated]

HIGH Netty CVE published 2026-05-13

CVE-2026-42584

Netty, an asynchronous network application framework, has a vulnerability in its HttpClientCodec component. Prior to versions 4.2.13.Final and 4.1.133.Final, the codec can misinterpret HTTP responses when requests are pipelined, potentially leading to incorrect parsing of message bodies. This issue arises when a client sends a GET request followed by a HEAD request, and the server responds with a 103 stat [truncated]

HIGH Netty CVE published 2026-05-13

CVE-2026-42583

Netty's Lz4FrameDecoder contains an uncontrolled resource consumption vulnerability (CWE-400/CWE-770) that allows remote attackers to trigger excessive memory allocation. The decoder allocates a ByteBuf sized to the attacker-supplied decompressedLength (up to 32 MB per block) before any LZ4 decompression occurs. A malicious peer can force this allocation with only 21-22 bytes of network traffic, making th [truncated]

MEDIUM netty CVE published 2026-05-13

CVE-2026-42581

Netty's HttpObjectDecoder contains an HTTP request smuggling vulnerability affecting HTTP/1.0 requests. When both Transfer-Encoding: chunked and Content-Length headers are present, the decoder strips the conflicting Content-Length header for HTTP/1.1 but fails to apply the same protection for HTTP/1.0. This causes Netty to decode the body as chunked while preserving Content-Length in the forwarded HttpMes [truncated]

MEDIUM Netty CVE published 2026-05-13

CVE-2026-42580

Netty's HTTP chunk size parser contains an integer overflow vulnerability that enables HTTP request smuggling attacks. The flaw occurs when parsing chunked transfer-encoding sizes, where a malformed chunk size value silently overflows the signed 32-bit integer type, causing Netty to misinterpret chunk boundaries. This can desynchronize the HTTP request/response stream between Netty-based servers and downs [truncated]

HIGH netty CVE published 2026-05-13

CVE-2026-42579

Netty's DNS codec fails to enforce RFC 1035 domain name constraints during encoding and decoding operations, creating a bidirectional attack surface. Malicious DNS responses can exploit the decoder, while attacker-influenced hostnames can exploit the encoder. The vulnerability affects Netty versions prior to 4.1.133.Final and 4.2.13.Final. This is a HIGH severity issue (CVSS 7.5) with network attack vecto [truncated]

HIGH netty CVE published 2026-05-13

CVE-2026-42577

## Summary Netty's epoll transport (versions 4.2.0.Final through 4.2.13.Final) fails to detect TCP RST packets on half-closed connections, causing stale channels to accumulate and, in certain code paths, triggering a 100% CPU busy-loop in the event loop thread. This denial-of-service condition requires no authentication and is remotely exploitable. ## Affected Versions - **Netty**: 4.2.0.Final to 4.2.13.F [truncated]

HIGH netty CVE published 2026-03-27

CVE-2026-33870

Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue. This vulnerability affects Netty-based systems, particularly those using versions prior to 4.1.132.Final and 4.2.10.Final. Defenders should assess exposure and apply patches to prevent potential attacks. The issue is a hi [truncated]