netty has 63 CVEs on record. Cadence is steady at roughly 35 per quarter. The busiest recent month was June 2026 with 19. The median CVSS is 7.5 (high), with 1 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-770 (17) and CWE-400 (16). Most affected products: netty (42), io.netty.incubator:netty-incubator-codec-bhttp (4), io.netty:netty-codec-classes-quic (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 35 prev 26
Weakness classes
Products
- netty 42
- io.netty.incubator:netty-incubator-codec-bhttp 4
- io.netty:netty-codec-classes-quic 2
- io.netty:netty-codec-http 2
- io.netty:netty-codec-http3 2
- io.netty:netty-handler-ssl-ocsp 2
Worst active — by depth score
CVE-2026-45674High· 8.7Netty is a network application framework for development of protocol servers and clients60CVE-2026-50011High· 7.5Netty is a network application framework for development of protocol servers and clients53CVE-2026-42587High· 7.5Netty is an asynchronous, event-driven network application framework53CVE-2026-42579High· 7.5Netty is an asynchronous, event-driven network application framework53CVE-2026-42578High· 7.5Netty is an asynchronous, event-driven network application framework53
netty vulnerabilities
CVEs affecting netty, newest first. Open any entry for full detail, references, and exploit status.
63 CVEsRSS
CVE-2026-42587High· 7.5PoCNetty is an asynchronous, event-driven network application framework
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb at…
CVE-2026-33871High· 7.5Netty is an asynchronous, event-driven network application framework
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUAT…
CVE-2026-33870High· 7.5PoCNetty is an asynchronous, event-driven network application framework
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request s…