netty-codec-smtp vulnerabilities
CVEs whose affected-version data names the netty-codec-smtp package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-93576High· 7.5A flaw was found in Netty netty-codec-smtp
A flaw was found in Netty netty-codec-smtp. The component does not properly validate Carriage Return (CR) and Line Feed (LF) characters in the SMTP command-name field. A remote attacker, if an application routes untrusted input into this…
▾ TwilightRed Hat · netty-codec-smtpEPSS 0.27%via NVD
CVE-2026-93563High· 7.5A flaw was found in Netty's `SmtpResponseDecoder` component
A flaw was found in Netty's `SmtpResponseDecoder` component. A remote attacker, acting as a malicious or man-in-the-middle (MITM) SMTP server, could exploit this by sending a specially crafted, unbounded multi-line SMTP response without …
▾ TwilightRed Hat · netty-codec-smtpEPSS 0.33%via NVD