VulnSea

netty has 63 CVEs on record. Cadence is steady at roughly 35 per quarter. The busiest recent month was June 2026 with 19. The median CVSS is 7.5 (high), with 1 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-770 (17) and CWE-400 (16). Most affected products: netty (42), io.netty.incubator:netty-incubator-codec-bhttp (4), io.netty:netty-codec-classes-quic (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
—
Last 90 days
35 prev 26

Products

  • netty 42
  • io.netty.incubator:netty-incubator-codec-bhttp 4
  • io.netty:netty-codec-classes-quic 2
  • io.netty:netty-codec-http 2
  • io.netty:netty-codec-http3 2
  • io.netty:netty-handler-ssl-ocsp 2
63
Total CVEs
1
Critical
0
CISA KEV
0
Exploited
netty vulnerabilities (CVEs) — page 3 · VulnSea