VulnSea

netty has 49 CVEs on record. Cadence is steady at roughly 21 per quarter. The busiest recent month was June 2026 with 19. The median CVSS is 7.5 (high), with 1 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-400 (13) and CWE-770 (12). Most affected products: netty (23), io.netty.incubator:netty-incubator-codec-bhttp (4), io.netty:netty-codec-http (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
Last 90 days
21 prev 28

Products

  • netty 23
  • io.netty.incubator:netty-incubator-codec-bhttp 4
  • io.netty:netty-codec-http 3
  • io.netty:netty-codec-classes-quic 2
  • io.netty:netty-codec-http3 2
  • io.netty:netty-handler 2
49
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

netty vulnerabilities

CVEs affecting netty, newest first. Open any entry for full detail, references, and exploit status.

49 CVEsRSS

CVE-2026-54251High· 8.7
1w ago

netty-incubator-codec-ohttp implements Oblivious HTTP (OHTTP) gateway and client functionality using Netty

netty-incubator-codec-ohttp implements Oblivious HTTP (OHTTP) gateway and client functionality using Netty. Prior to 0.0.23.Final, the OHTTP gateway decryption path in codec-ohttp/src/main/java/io/netty/incubator/codec/ohttp/OHttpRequest…

Twilightnetty · netty-incubator-codec-ohttpEPSS 0.29%via NVD
CVE-2026-89044Medium· 6.5
1w ago

Netty versions 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final fail to properly validate the final transfer coding in the Transfer-Encoding header, allowing attackers to smuggle requests by using malformed encod…

Netty versions 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final fail to properly validate the final transfer coding in the Transfer-Encoding header, allowing attackers to smuggle requests by using malformed encod…

Sunlitnetty · nettyEPSS 0.24%via NVD
CVE-2026-61798High· 8.1
1mo ago

netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messages

netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messages

Twilightnetty · io.netty.incubator:netty-incubator-codec-ohttp-hpke-classes-boringsslvia GHSA
CVE-2026-61799Medium· 5.3
1mo ago

netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash

netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash

Sunlitnetty · io.netty.incubator:netty-incubator-codec-bhttpvia GHSA
CVE-2026-63124High· 7.5
1mo ago

netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length field section boundary

netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length field section boundary

Twilightnetty · io.netty.incubator:netty-incubator-codec-bhttpvia GHSA
CVE-2026-61827High
1mo ago

netty-incubator-codec-ohttp: BinaryHttpParser should enforce limits for variable lengths fields

netty-incubator-codec-ohttp: BinaryHttpParser should enforce limits for variable lengths fields

Twilightnetty · io.netty.incubator:netty-incubator-codec-bhttpvia GHSA
CVE-2026-63202High· 7.5
1mo ago

netty-incubator-codec-ohttp BinaryHttpParser: Unauthenticated CPU-exhaustion DoS via infinite loop in field-section decoding

netty-incubator-codec-ohttp BinaryHttpParser: Unauthenticated CPU-exhaustion DoS via infinite loop in field-section decoding

Twilightnetty · io.netty.incubator:netty-incubator-codec-bhttpvia GHSA
CVE-2026-75596Medium
1mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, the default io.netty.handler.ssl.SniHandler constructors use the pre-handshake ClientHello aggregation path in handler/src/mai…

Sunlitnetty · io.netty:netty-handlerEPSS 0.35%via NVD
CVE-2026-75595Critical· 7.4
1mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.handler.ssl.SslClientHelloHandler#decode checks the wrong offset before reading the four-byte TLS handshake header, so…

Midnightnetty · io.netty:netty-handlerEPSS 0.32%via NVD
CVE-2026-59903Medium· 6.5PoC
1mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.http.cors.CorsHandler setVaryHeader replaces application Vary headers such as Authorization or Cookie w…

Twilightnetty · io.netty:netty-codec-httpEPSS 0.24%via NVD
CVE-2026-59902High· 7.5
1mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.sctp.SctpMessageCompletionHandler limits incomplete messages and fragment counts but not maxBufferedByt…

Twilightnetty · io.netty:netty-transport-sctpEPSS 0.37%via NVD
CVE-2026-56818Medium· 6.5
1mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the RedisArrayAggregator Redis codec clears retained partial aggregate state when the maxNestedArrayDepth limit is exceeded, b…

Sunlitnetty · io.netty:netty-codec-redisEPSS 0.28%via NVD
GHSA-mfg7-5gfp-c4w3Medium· 5.3
2mo ago

Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names

Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names

Sunlitnetty · io.netty:netty-codec-dnsvia GHSA
GHSA-v74w-7mr3-4qg3High· 7.5
2mo ago

Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion

Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion

Twilightnetty · io.netty:netty-codec-xmlvia GHSA
CVE-2026-56821High· 7.4
2mo ago

Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator

Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator

Twilightnetty · io.netty:netty-handler-ssl-ocspEPSS 0.16%via GHSA
CVE-2026-56822High· 7.4
2mo ago

Netty: TOCTOU in OcspServerCertificateValidator

Netty: TOCTOU in OcspServerCertificateValidator

Twilightnetty · io.netty:netty-handler-ssl-ocspEPSS 0.11%via GHSA
CVE-2026-59898Medium
2mo ago

Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation

Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation

Sunlitnetty · io.netty:netty-codec-httpEPSS 0.25%via GHSA
CVE-2026-59900Medium
2mo ago

Netty: [codec-http2] Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass

Netty: [codec-http2] Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass

Sunlitnetty · io.netty:netty-codec-http2EPSS 0.23%via GHSA
CVE-2026-59919Medium· 5.5
2mo ago

Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address

Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address

Sunlitnetty · io.netty:netty-codec-haproxyEPSS 0.14%via GHSA
CVE-2026-59920Medium· 6.5
2mo ago

Netty: STOMP CONNECT Frame Header Injection in Netty

Netty: STOMP CONNECT Frame Header Injection in Netty

Sunlitnetty · io.netty:netty-codec-stompEPSS 0.24%via GHSA
CVE-2026-59921Medium· 5.7
2mo ago

Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder

Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder

Sunlitnetty · io.netty:netty-codec-httpEPSS 0.25%via GHSA
CVE-2026-48480Medium
3mo ago

OHttpVersionChunkDraft: Missing Final-Chunk Enforcement Leads to Undetected Stream Truncation

OHttpVersionChunkDraft: Missing Final-Chunk Enforcement Leads to Undetected Stream Truncation

Sunlitnetty · io.netty.incubator:netty-incubator-codec-ohttpEPSS 0.17%via GHSA
CVE-2026-48748High· 7.5
3mo ago

Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion

Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion

Twilightnetty · io.netty:netty-codec-http3EPSS 0.39%via GHSA
CVE-2026-50009Medium· 4.8
3mo ago

Netty: QUIC stateless reset token material exposed through header-visible connection IDs

Netty: QUIC stateless reset token material exposed through header-visible connection IDs

Sunlitnetty · io.netty:netty-codec-classes-quicEPSS 0.20%via GHSA
CVE-2026-46340High· 7.5
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. In versions of netty-transport-sctp prior to 4.1.135.Final and 4.2.15.Final, for each non-complete SctpMessage fragment the handler does `fragments…

Twilightnetty · nettyEPSS 0.61%via NVD
CVE-2026-48006High· 7.5
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the RedisArrayAggregator handler permanently leaks pooled direct-memory buffers when a Redis pipe…

Twilightnetty · nettyEPSS 0.74%via NVD
CVE-2026-50011High· 7.5PoC
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, RedisArrayAggregator pre-allocates ArrayList with initial capacity equal to the RESP array elemen…

Midnightnetty · nettyEPSS 0.46%via NVD
CVE-2026-50010High· 7.5
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SimpleTrustManagerFactory.engineGetTrustManagers() and related paths wrap any user-supplied plain…

Twilightnetty · nettyEPSS 0.49%via NVD
CVE-2026-48059High· 7.5
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the HAProxy PROXY protocol v2 codec in netty leaks native or heap memory on every connection when…

Twilightnetty · nettyEPSS 0.63%via NVD
CVE-2026-48043Medium· 5.3⚖ disputed
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. In netty-codec-http2 prior to versions 4.1.135.Final and 4.2.15.Final, the `DelegatingDecompressorFrameListener` class orchestrates HTTP/2 decompre…

Sunlitnetty · nettyEPSS 0.75%via NVD
netty vulnerabilities (CVEs) · VulnSea