CWE-475
CVEs classified under CWE-475, newest first.
2 CVEsRSS
CVE-2026-75595Critical· 7.4Netty is an asynchronous, event-driven network application framework
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.handler.ssl.SslClientHelloHandler#decode checks the wrong offset before reading the four-byte TLS handshake header, so…
▾ Midnightnetty · io.netty:netty-handlerEPSS 0.32%via NVD
CVE-2026-42009High· 7.5A flaw was found in gnutls
A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not cor…
▾ Twilightgnu · gnutlsEPSS 1.3%via NVD