VulnSea

netty has 63 CVEs on record. Cadence is steady at roughly 35 per quarter. The busiest recent month was June 2026 with 19. The median CVSS is 7.5 (high), with 1 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-400 (16) and CWE-770 (16). Most affected products: netty (42), io.netty.incubator:netty-incubator-codec-bhttp (4), io.netty:netty-codec-classes-quic (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
—
Last 90 days
35 prev 26

Products

  • netty 42
  • io.netty.incubator:netty-incubator-codec-bhttp 4
  • io.netty:netty-codec-classes-quic 2
  • io.netty:netty-codec-http 2
  • io.netty:netty-codec-http3 2
  • io.netty:netty-handler-ssl-ocsp 2
63
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

netty vulnerabilities

CVEs affecting netty, newest first. Open any entry for full detail, references, and exploit status.

63 CVEsRSS

CVE-2026-59898Medium
2mo ago

Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation

Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation

▾ Sunlitnetty · io.netty:netty-codec-httpEPSS 0.44%via GHSA
CVE-2026-59900Medium
2mo ago

Netty: [codec-http2] Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass

Netty: [codec-http2] Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass

▾ Sunlitnetty · io.netty:netty-codec-http2EPSS 0.40%via GHSA
CVE-2026-59919Medium· 5.5
2mo ago

Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address

Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address

▾ Sunlitnetty · io.netty:netty-codec-haproxyEPSS 0.17%via GHSA
CVE-2026-59920Medium· 6.5
2mo ago

Netty: STOMP CONNECT Frame Header Injection in Netty

Netty: STOMP CONNECT Frame Header Injection in Netty

▾ Sunlitnetty · io.netty:netty-codec-stompEPSS 0.41%via GHSA
CVE-2026-59921Medium· 5.7
2mo ago

Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder

Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder

▾ Sunlitnetty · io.netty:netty-codec-httpEPSS 0.46%via GHSA
CVE-2026-48480Medium
3mo ago

OHttpVersionChunkDraft: Missing Final-Chunk Enforcement Leads to Undetected Stream Truncation

OHttpVersionChunkDraft: Missing Final-Chunk Enforcement Leads to Undetected Stream Truncation

▾ Sunlitnetty · io.netty.incubator:netty-incubator-codec-ohttpEPSS 0.27%via GHSA
CVE-2026-48748High· 7.5
3mo ago

Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion

Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion

▾ Twilightnetty · io.netty:netty-codec-http3EPSS 0.68%via GHSA
CVE-2026-50009Medium· 4.8
3mo ago

Netty: QUIC stateless reset token material exposed through header-visible connection IDs

Netty: QUIC stateless reset token material exposed through header-visible connection IDs

▾ Sunlitnetty · io.netty:netty-codec-classes-quicEPSS 0.32%via GHSA
CVE-2026-46340High· 7.5
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. In versions of netty-transport-sctp prior to 4.1.135.Final and 4.2.15.Final, for each non-complete SctpMessage fragment the handler does `fragments…

▾ Twilightnetty · nettyEPSS 0.85%via NVD
CVE-2026-48006High· 7.5
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the RedisArrayAggregator handler permanently leaks pooled direct-memory buffers when a Redis pipe…

▾ Twilightnetty · nettyEPSS 0.85%via NVD
CVE-2026-50011High· 7.5PoC
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, RedisArrayAggregator pre-allocates ArrayList with initial capacity equal to the RESP array elemen…

▾ Midnightnetty · nettyEPSS 0.85%via NVD
CVE-2026-50010High· 7.5
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SimpleTrustManagerFactory.engineGetTrustManagers() and related paths wrap any user-supplied plain…

▾ Twilightnetty · nettyEPSS 0.72%via NVD
CVE-2026-48059High· 7.5
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the HAProxy PROXY protocol v2 codec in netty leaks native or heap memory on every connection when…

▾ Twilightnetty · nettyEPSS 0.88%via NVD
CVE-2026-48043Medium· 5.3⚖ disputed
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. In netty-codec-http2 prior to versions 4.1.135.Final and 4.2.15.Final, the `DelegatingDecompressorFrameListener` class orchestrates HTTP/2 decompre…

▾ Sunlitnetty · nettyEPSS 0.88%via NVD
CVE-2026-47691High· 8.7
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's `DnsResolveContext` insufficiently validates the bailiwick of NS records, enabling DNS Ca…

▾ Twilightnetty · nettyEPSS 0.36%via NVD
CVE-2026-45674High· 8.7PoC
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS respon…

▾ Midnightnetty · nettyEPSS 0.36%via NVD
CVE-2026-45416High· 7.5
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SslClientHelloHandler.decode() reads the 24-bit TLS handshake length and, when the ClientHello do…

▾ Twilightnetty · nettyEPSS 1.6%via NVD
CVE-2026-44893High· 7.5
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. In netty-codec-haproxy prior to versions 4.1.135.Final and 4.2.15.Final, when decoding a PP2_TYPE_SSL TLV, HAProxyMessage.readNextTLV() first calls…

▾ Twilightnetty · nettyEPSS 0.88%via NVD
CVE-2026-44250High· 7.5
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can cause DoS by sending a crafted Redis payload with deeply nes…

▾ Twilightnetty · nettyEPSS 0.85%via NVD
CVE-2026-44890High· 7.5
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can cause DoS by sending crafted Redis payloads across multiple …

▾ Twilightnetty · nettyEPSS 0.85%via NVD
CVE-2026-48040Medium
3mo ago

netty-incubator-codec-ohttp's Incorrect Native Pointer Derivation in Pooled Direct ByteBuf Fallback Leads to Out-of-Bounds Native Memory Access

netty-incubator-codec-ohttp's Incorrect Native Pointer Derivation in Pooled Direct ByteBuf Fallback Leads to Out-of-Bounds Native Memory Access

▾ Sunlitnetty · io.netty.incubator:netty-incubator-codec-ohttp-hpke-native-boringsslEPSS 0.29%via GHSA
CVE-2026-44249High· 8.1
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation i…

▾ Twilightnetty · nettyEPSS 1.3%via NVD
CVE-2026-44892High· 7.5
3mo ago

Netty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header Size

Netty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header Size

▾ Twilightnetty · io.netty:netty-codec-http3EPSS 0.49%via GHSA
CVE-2026-44894High· 7.5
3mo ago

Netty's Default QUIC token handler accepts any client-supplied token

Netty's Default QUIC token handler accepts any client-supplied token

▾ Twilightnetty · io.netty:netty-codec-classes-quicEPSS 0.19%via GHSA
CVE-2026-44248Medium· 5.3⚖ disputed
4mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDec…

▾ Sunlitnetty · nettyEPSS 0.72%via NVD
CVE-2026-42582High· 7.5
4mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byt…

▾ Twilightnetty · nettyEPSS 0.49%via NVD
CVE-2026-42584High· 7.3PoC
4mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If …

▾ Midnightnetty · nettyEPSS 0.72%via NVD
CVE-2026-42581Medium· 5.8PoC
4mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Conten…

▾ Twilightnetty · nettyEPSS 0.68%via NVD
CVE-2026-42579High· 7.5PoC
4mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirec…

▾ Midnightnetty · nettyEPSS 0.85%via NVD
CVE-2026-42578High· 7.5PoC⚖ disputed
4mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() …

▾ Midnightnetty · nettyEPSS 1.2%via NVD
netty vulnerabilities (CVEs) — page 2 · VulnSea