CVE-2026-56817High· 7.5▾ TwilightA flaw was found in Netty, a network application framework. A remote attacker could exploit this vulnerability by sending specially crafted XML data containing a DOCTYPE declaration to a vulnerable XmlDecoder within the Netty channel pipel…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 22.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.6%
Last analysed / modified upstream
— → 7.5
0.6% → 0.7%
A flaw was found in Netty, a network application framework. A remote attacker could exploit this vulnerability by sending specially crafted XML data containing a DOCTYPE declaration to a vulnerable XmlDecoder within the Netty channel pipeline. This can lead to an XML External Entity (XXE) vulnerability, potentially allowing the attacker to disclose sensitive information from the system.
io.netty/netty-codec-xml: Netty: Information disclosure via XML External Entity (XXE) vulnerability — rated Important by Red Hat. Released 2026-07-21, updated 2026-09-21.
Affected:
Fixed:
No fix planned:
Not affected:
Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:69296 Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:54622
Workarounds / mitigations:
Affected packages:
io.netty:netty-codec-xml >= 4.2.0.Final, <= 4.2.15.Finalio.netty:netty-codec-xml >= 4.1.0.Final, <= 4.1.135.FinalPatched in:
io.netty:netty-codec-xml 4.2.16.Finalio.netty:netty-codec-xml 4.1.136.FinalField changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-44891High· 7.5io.netty/netty-codec-stomp: Netty: Denial of Service vulnerability in STOMP decoder (CVE-2026-44891)
CVE-2026-17615High· 7.5A flaw was found in RESTEasy's SourceProvider
CVE-2026-76816Low· 3.5Netty is an asynchronous, event-driven network application framework
CVE-2026-59649High· 7.5In Bouncy Castle for Java before 1.85, OpenPGP user-attribute subpacket length bounded only by JVM max memory
CVE-2026-97846Medium· 6.8Keycloak provides a feature called mTLS holder-of-key binding which ensures that a token can only be used by the client that originally requested it by binding it to their digital certificate
CVE-2026-95811Medium· 5.4Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow an equivalent spelling of a path to bypass the locationRules that restrict it. The handler matches each vhost…