io.netty:netty-handler vulnerabilities
CVEs whose affected-version data names the io.netty:netty-handler package (maven). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-75596MediumNetty is an asynchronous, event-driven network application framework
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, the default io.netty.handler.ssl.SniHandler constructors use the pre-handshake ClientHello aggregation path in handler/src/mai…
▾ Sunlitnetty · io.netty:netty-handlerEPSS 0.35%via NVD
CVE-2026-75595Critical· 7.4Netty is an asynchronous, event-driven network application framework
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.handler.ssl.SslClientHelloHandler#decode checks the wrong offset before reading the four-byte TLS handshake header, so…
▾ Midnightnetty · io.netty:netty-handlerEPSS 0.32%via NVD