netty has 49 CVEs on record. Cadence is steady at roughly 21 per quarter. The busiest recent month was June 2026 with 19. The median CVSS is 7.5 (high), with 1 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-400 (13) and CWE-770 (12). Most affected products: netty (23), io.netty.incubator:netty-incubator-codec-bhttp (4), io.netty:netty-codec-http (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 21 prev 28
Weakness classes
Products
- netty 23
- io.netty.incubator:netty-incubator-codec-bhttp 4
- io.netty:netty-codec-http 3
- io.netty:netty-codec-classes-quic 2
- io.netty:netty-codec-http3 2
- io.netty:netty-handler 2
Worst active — by depth score
CVE-2026-45674High· 8.7Netty is a network application framework for development of protocol servers and clients60CVE-2026-50011High· 7.5Netty is a network application framework for development of protocol servers and clients53CVE-2026-42587High· 7.5Netty is an asynchronous, event-driven network application framework53CVE-2026-42579High· 7.5Netty is an asynchronous, event-driven network application framework53CVE-2026-42578High· 7.5Netty is an asynchronous, event-driven network application framework53
netty vulnerabilities
CVEs affecting netty, newest first. Open any entry for full detail, references, and exploit status.
49 CVEsRSS
CVE-2026-54251High· 8.7netty-incubator-codec-ohttp implements Oblivious HTTP (OHTTP) gateway and client functionality using Netty
netty-incubator-codec-ohttp implements Oblivious HTTP (OHTTP) gateway and client functionality using Netty. Prior to 0.0.23.Final, the OHTTP gateway decryption path in codec-ohttp/src/main/java/io/netty/incubator/codec/ohttp/OHttpRequest…
CVE-2026-89044Medium· 6.5Netty versions 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final fail to properly validate the final transfer coding in the Transfer-Encoding header, allowing attackers to smuggle requests by using malformed encod…
Netty versions 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final fail to properly validate the final transfer coding in the Transfer-Encoding header, allowing attackers to smuggle requests by using malformed encod…
CVE-2026-61798High· 8.1netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messages
netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messages
CVE-2026-61799Medium· 5.3netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash
netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash
CVE-2026-63124High· 7.5netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length field section boundary
netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length field section boundary
CVE-2026-61827Highnetty-incubator-codec-ohttp: BinaryHttpParser should enforce limits for variable lengths fields
netty-incubator-codec-ohttp: BinaryHttpParser should enforce limits for variable lengths fields
CVE-2026-63202High· 7.5netty-incubator-codec-ohttp BinaryHttpParser: Unauthenticated CPU-exhaustion DoS via infinite loop in field-section decoding
netty-incubator-codec-ohttp BinaryHttpParser: Unauthenticated CPU-exhaustion DoS via infinite loop in field-section decoding
CVE-2026-75596MediumNetty is an asynchronous, event-driven network application framework
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, the default io.netty.handler.ssl.SniHandler constructors use the pre-handshake ClientHello aggregation path in handler/src/mai…
CVE-2026-75595Critical· 7.4Netty is an asynchronous, event-driven network application framework
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.handler.ssl.SslClientHelloHandler#decode checks the wrong offset before reading the four-byte TLS handshake header, so…
CVE-2026-59903Medium· 6.5PoCNetty is an asynchronous, event-driven network application framework
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.http.cors.CorsHandler setVaryHeader replaces application Vary headers such as Authorization or Cookie w…
CVE-2026-59902High· 7.5Netty is an asynchronous, event-driven network application framework
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.sctp.SctpMessageCompletionHandler limits incomplete messages and fragment counts but not maxBufferedByt…
CVE-2026-56818Medium· 6.5Netty is an asynchronous, event-driven network application framework
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the RedisArrayAggregator Redis codec clears retained partial aggregate state when the maxNestedArrayDepth limit is exceeded, b…
GHSA-mfg7-5gfp-c4w3Medium· 5.3Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names
Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names
GHSA-v74w-7mr3-4qg3High· 7.5Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion
Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion
CVE-2026-56821High· 7.4Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator
Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator
CVE-2026-56822High· 7.4Netty: TOCTOU in OcspServerCertificateValidator
Netty: TOCTOU in OcspServerCertificateValidator
CVE-2026-59898MediumNetty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation
Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation
CVE-2026-59900MediumNetty: [codec-http2] Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass
Netty: [codec-http2] Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass
CVE-2026-59919Medium· 5.5Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address
Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address
CVE-2026-59920Medium· 6.5Netty: STOMP CONNECT Frame Header Injection in Netty
Netty: STOMP CONNECT Frame Header Injection in Netty
CVE-2026-59921Medium· 5.7Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
CVE-2026-48480MediumOHttpVersionChunkDraft: Missing Final-Chunk Enforcement Leads to Undetected Stream Truncation
OHttpVersionChunkDraft: Missing Final-Chunk Enforcement Leads to Undetected Stream Truncation
CVE-2026-48748High· 7.5Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion
Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion
CVE-2026-50009Medium· 4.8Netty: QUIC stateless reset token material exposed through header-visible connection IDs
Netty: QUIC stateless reset token material exposed through header-visible connection IDs
CVE-2026-46340High· 7.5Netty is a network application framework for development of protocol servers and clients
Netty is a network application framework for development of protocol servers and clients. In versions of netty-transport-sctp prior to 4.1.135.Final and 4.2.15.Final, for each non-complete SctpMessage fragment the handler does `fragments…
CVE-2026-48006High· 7.5Netty is a network application framework for development of protocol servers and clients
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the RedisArrayAggregator handler permanently leaks pooled direct-memory buffers when a Redis pipe…
CVE-2026-50011High· 7.5PoCNetty is a network application framework for development of protocol servers and clients
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, RedisArrayAggregator pre-allocates ArrayList with initial capacity equal to the RESP array elemen…
CVE-2026-50010High· 7.5Netty is a network application framework for development of protocol servers and clients
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SimpleTrustManagerFactory.engineGetTrustManagers() and related paths wrap any user-supplied plain…
CVE-2026-48059High· 7.5Netty is a network application framework for development of protocol servers and clients
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the HAProxy PROXY protocol v2 codec in netty leaks native or heap memory on every connection when…
CVE-2026-48043Medium· 5.3⚖ disputedNetty is a network application framework for development of protocol servers and clients
Netty is a network application framework for development of protocol servers and clients. In netty-codec-http2 prior to versions 4.1.135.Final and 4.2.15.Final, the `DelegatingDecompressorFrameListener` class orchestrates HTTP/2 decompre…