CVE-2026-59903Medium· 6.5▾ TwilightPoC availableNetty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.http.cors.CorsHandler setVaryHeader replaces application Vary headers such as Authorization or Cookie w…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 35.8 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Aug 18.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.4%
Last analysed / modified upstream
1 GitHub repo
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.http.cors.CorsHandler setVaryHeader replaces application Vary headers such as Authorization or Cookie with Origin, allowing a caching proxy or CDN to reuse authenticated responses across users and disclose sensitive information. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
io.netty:netty-codec-http >= 4.2.0.Final, <= 4.2.16.Finalio.netty:netty-codec-http <= 4.1.136.FinalPatched in:
io.netty:netty-codec-http 4.2.17.Finalio.netty:netty-codec-http 4.1.137.FinalSource: https://github.com/advisories/GHSA-8c42-7qj2-3j46
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-75595Critical· 7.4Netty is an asynchronous, event-driven network application framework
CVE-2026-59902High· 7.5Netty is an asynchronous, event-driven network application framework
CVE-2026-75596MediumNetty is an asynchronous, event-driven network application framework
CVE-2026-42584High· 7.3Netty is an asynchronous, event-driven network application framework
CVE-2026-42581Medium· 5.8Netty is an asynchronous, event-driven network application framework
CVE-2026-33870High· 7.5Netty is an asynchronous, event-driven network application framework