io.netty:netty-codec-http3 vulnerabilities
CVEs whose affected-version data names the io.netty:netty-codec-http3 package (maven). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-48748High· 7.5Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion
Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion
▾ Twilightnetty · io.netty:netty-codec-http3EPSS 0.39%via GHSA
CVE-2026-44892High· 7.5Netty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header Size
Netty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header Size
▾ Twilightnetty · io.netty:netty-codec-http3EPSS 0.28%via GHSA