netty has 63 CVEs on record. Cadence is steady at roughly 35 per quarter. The busiest recent month was June 2026 with 19. The median CVSS is 7.5 (high), with 1 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-400 (16) and CWE-770 (16). Most affected products: netty (42), io.netty.incubator:netty-incubator-codec-bhttp (4), io.netty:netty-codec-classes-quic (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 35 prev 26
Weakness classes
Products
- netty 42
- io.netty.incubator:netty-incubator-codec-bhttp 4
- io.netty:netty-codec-classes-quic 2
- io.netty:netty-codec-http 2
- io.netty:netty-codec-http3 2
- io.netty:netty-handler-ssl-ocsp 2
Worst active — by depth score
CVE-2026-45674High· 8.7Netty is a network application framework for development of protocol servers and clients60CVE-2026-50011High· 7.5Netty is a network application framework for development of protocol servers and clients53CVE-2026-42587High· 7.5Netty is an asynchronous, event-driven network application framework53CVE-2026-42579High· 7.5Netty is an asynchronous, event-driven network application framework53CVE-2026-42578High· 7.5Netty is an asynchronous, event-driven network application framework53
netty vulnerabilities
CVEs affecting netty, newest first. Open any entry for full detail, references, and exploit status.
63 CVEsRSS
CVE-2026-59898MediumNetty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation
Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation
CVE-2026-59900MediumNetty: [codec-http2] Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass
Netty: [codec-http2] Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass
CVE-2026-59919Medium· 5.5Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address
Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address
CVE-2026-59920Medium· 6.5Netty: STOMP CONNECT Frame Header Injection in Netty
Netty: STOMP CONNECT Frame Header Injection in Netty
CVE-2026-59921Medium· 5.7Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
CVE-2026-48480MediumOHttpVersionChunkDraft: Missing Final-Chunk Enforcement Leads to Undetected Stream Truncation
OHttpVersionChunkDraft: Missing Final-Chunk Enforcement Leads to Undetected Stream Truncation
CVE-2026-48748High· 7.5Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion
Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion
CVE-2026-50009Medium· 4.8Netty: QUIC stateless reset token material exposed through header-visible connection IDs
Netty: QUIC stateless reset token material exposed through header-visible connection IDs
CVE-2026-46340High· 7.5Netty is a network application framework for development of protocol servers and clients
Netty is a network application framework for development of protocol servers and clients. In versions of netty-transport-sctp prior to 4.1.135.Final and 4.2.15.Final, for each non-complete SctpMessage fragment the handler does `fragments…
CVE-2026-48006High· 7.5Netty is a network application framework for development of protocol servers and clients
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the RedisArrayAggregator handler permanently leaks pooled direct-memory buffers when a Redis pipe…
CVE-2026-50011High· 7.5PoCNetty is a network application framework for development of protocol servers and clients
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, RedisArrayAggregator pre-allocates ArrayList with initial capacity equal to the RESP array elemen…
CVE-2026-50010High· 7.5Netty is a network application framework for development of protocol servers and clients
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SimpleTrustManagerFactory.engineGetTrustManagers() and related paths wrap any user-supplied plain…
CVE-2026-48059High· 7.5Netty is a network application framework for development of protocol servers and clients
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the HAProxy PROXY protocol v2 codec in netty leaks native or heap memory on every connection when…
CVE-2026-48043Medium· 5.3⚖ disputedNetty is a network application framework for development of protocol servers and clients
Netty is a network application framework for development of protocol servers and clients. In netty-codec-http2 prior to versions 4.1.135.Final and 4.2.15.Final, the `DelegatingDecompressorFrameListener` class orchestrates HTTP/2 decompre…
CVE-2026-47691High· 8.7Netty is a network application framework for development of protocol servers and clients
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's `DnsResolveContext` insufficiently validates the bailiwick of NS records, enabling DNS Ca…
CVE-2026-45674High· 8.7PoCNetty is a network application framework for development of protocol servers and clients
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS respon…
CVE-2026-45416High· 7.5Netty is a network application framework for development of protocol servers and clients
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SslClientHelloHandler.decode() reads the 24-bit TLS handshake length and, when the ClientHello do…
CVE-2026-44893High· 7.5Netty is a network application framework for development of protocol servers and clients
Netty is a network application framework for development of protocol servers and clients. In netty-codec-haproxy prior to versions 4.1.135.Final and 4.2.15.Final, when decoding a PP2_TYPE_SSL TLV, HAProxyMessage.readNextTLV() first calls…
CVE-2026-44250High· 7.5Netty is a network application framework for development of protocol servers and clients
Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can cause DoS by sending a crafted Redis payload with deeply nes…
CVE-2026-44890High· 7.5Netty is a network application framework for development of protocol servers and clients
Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can cause DoS by sending crafted Redis payloads across multiple …
CVE-2026-48040Mediumnetty-incubator-codec-ohttp's Incorrect Native Pointer Derivation in Pooled Direct ByteBuf Fallback Leads to Out-of-Bounds Native Memory Access
netty-incubator-codec-ohttp's Incorrect Native Pointer Derivation in Pooled Direct ByteBuf Fallback Leads to Out-of-Bounds Native Memory Access
CVE-2026-44249High· 8.1Netty is a network application framework for development of protocol servers and clients
Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation i…
CVE-2026-44892High· 7.5Netty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header Size
Netty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header Size
CVE-2026-44894High· 7.5Netty's Default QUIC token handler accepts any client-supplied token
Netty's Default QUIC token handler accepts any client-supplied token
CVE-2026-44248Medium· 5.3⚖ disputedNetty is an asynchronous, event-driven network application framework
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDec…
CVE-2026-42582High· 7.5Netty is an asynchronous, event-driven network application framework
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byt…
CVE-2026-42584High· 7.3PoCNetty is an asynchronous, event-driven network application framework
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If …
CVE-2026-42581Medium· 5.8PoCNetty is an asynchronous, event-driven network application framework
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Conten…
CVE-2026-42579High· 7.5PoCNetty is an asynchronous, event-driven network application framework
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirec…
CVE-2026-42578High· 7.5PoC⚖ disputedNetty is an asynchronous, event-driven network application framework
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() …