Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
CVE-2026-54251High· 8.7netty-incubator-codec-ohttp implements Oblivious HTTP (OHTTP) gateway and client functionality using Netty. Prior to 0.0.23.Final, the OHTTP gateway decryption path in codec-ohttp/src/main/java/io/netty/incubator/codec/ohttp/OHttpRequest…
CVE-2026-89044Medium· 6.5Netty versions 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final fail to properly validate the final transfer coding in the Transfer-Encoding header, allowing attackers to smuggle requests by using malformed encod…
CVE-2026-61798High· 8.1netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messages
CVE-2026-61799Medium· 5.3netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash
CVE-2026-63124High· 7.5netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length field section boundary
CVE-2026-61827Highnetty-incubator-codec-ohttp: BinaryHttpParser should enforce limits for variable lengths fields
CVE-2026-63202High· 7.5netty-incubator-codec-ohttp BinaryHttpParser: Unauthenticated CPU-exhaustion DoS via infinite loop in field-section decoding
CVE-2026-75596MediumNetty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, the default io.netty.handler.ssl.SniHandler constructors use the pre-handshake ClientHello aggregation path in handler/src/mai…
CVE-2026-75595Critical· 7.4Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.handler.ssl.SslClientHelloHandler#decode checks the wrong offset before reading the four-byte TLS handshake header, so…
CVE-2026-59903Medium· 6.5PoCNetty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.http.cors.CorsHandler setVaryHeader replaces application Vary headers such as Authorization or Cookie w…
CVE-2026-59902High· 7.5Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.sctp.SctpMessageCompletionHandler limits incomplete messages and fragment counts but not maxBufferedByt…
CVE-2026-56818Medium· 6.5Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the RedisArrayAggregator Redis codec clears retained partial aggregate state when the maxNestedArrayDepth limit is exceeded, b…
GHSA-mfg7-5gfp-c4w3Medium· 5.3Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names
GHSA-v74w-7mr3-4qg3High· 7.5Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion
CVE-2026-56821High· 7.4Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator
CVE-2026-56822High· 7.4Netty: TOCTOU in OcspServerCertificateValidator
CVE-2026-59898MediumNetty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation
CVE-2026-59900MediumNetty: [codec-http2] Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass
CVE-2026-59919Medium· 5.5Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address
CVE-2026-59920Medium· 6.5Netty: STOMP CONNECT Frame Header Injection in Netty
CVE-2026-59921Medium· 5.7Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
CVE-2026-48480MediumOHttpVersionChunkDraft: Missing Final-Chunk Enforcement Leads to Undetected Stream Truncation
CVE-2026-48748High· 7.5Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion
CVE-2026-50009Medium· 4.8Netty: QUIC stateless reset token material exposed through header-visible connection IDs
CVE-2026-46340High· 7.5Netty is a network application framework for development of protocol servers and clients. In versions of netty-transport-sctp prior to 4.1.135.Final and 4.2.15.Final, for each non-complete SctpMessage fragment the handler does `fragments…
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.