io.netty:netty-codec-classes-quic vulnerabilities
CVEs whose affected-version data names the io.netty:netty-codec-classes-quic package (maven). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-50009Medium· 4.8Netty: QUIC stateless reset token material exposed through header-visible connection IDs
Netty: QUIC stateless reset token material exposed through header-visible connection IDs
▾ Sunlitnetty · io.netty:netty-codec-classes-quicEPSS 0.20%via GHSA
CVE-2026-44894High· 7.5Netty's Default QUIC token handler accepts any client-supplied token
Netty's Default QUIC token handler accepts any client-supplied token
▾ Twilightnetty · io.netty:netty-codec-classes-quicEPSS 0.14%via GHSA