io.netty:netty-codec-http vulnerabilities
CVEs whose affected-version data names the io.netty:netty-codec-http package (maven). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-59903Medium· 6.5PoCNetty is an asynchronous, event-driven network application framework
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.http.cors.CorsHandler setVaryHeader replaces application Vary headers such as Authorization or Cookie w…
▾ Twilightnetty · io.netty:netty-codec-httpEPSS 0.24%via NVD
CVE-2026-59898MediumNetty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation
Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation
▾ Sunlitnetty · io.netty:netty-codec-httpEPSS 0.25%via GHSA
CVE-2026-59921Medium· 5.7Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
▾ Sunlitnetty · io.netty:netty-codec-httpEPSS 0.25%via GHSA