Netty
Netty: vulnerabilidades y CVE
Netty tiene 119 vulnerabilidades publicadas, 90 de ellas en los últimos 12 meses. 9 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE119
Últimos 12 meses90
Críticas9
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-44487 | Alta (7.5) | 100% | ⚠ Explotación activa | 10 oct 2023 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-100665 | Alta (8.7) | 0.29% | — | 26 sept 2026 | Netty versions from 4.2.11.Final before 4.2.18.Final contain an incomplete hostname verification fix in the QUIC certificate verification path when using a plain X509TrustManager. The BoringSSLCertificateVerifyCallback… |
| CVE-2026-93562 | Media (6.5) | 0.58% | — | 18 sept 2026 | A flaw was found in Netty's HTTP/1 decoder. Incomplete validation of malformed Transfer-Encoding headers allows a remote attacker to perform HTTP request smuggling. By sending specially crafted HTTP requests, an… |
| CVE-2026-93579 | Media (6.5) | 0.58% | — | 18 sept 2026 | A flaw was found in Netty's HTTP/2 stack. This vulnerability allows a remote attacker to inject prohibited characters, such as NUL, Line Feed, and Carriage Return, into HTTP/2 header field values due to insufficient… |
| CVE-2026-93573 | Media (6.5) | 0.58% | — | 18 sept 2026 | A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allows a remote attacker to bypass `Transfer-Encoding` header validation by splitting the `Transfer-Encoding` field across multiple headers, with the last… |
| CVE-2026-93569 | Alta (8.2) | 0.70% | — | 18 sept 2026 | A flaw was found in Netty. A remote unauthenticated attacker can exploit a vulnerability in Netty's HTTP/1 to HTTP/2 conversion process. When an HTTP/1 request includes both an absolute-form request-target and a… |
| CVE-2026-93568 | Alta (7.5) | 0.77% | — | 18 sept 2026 | A flaw was found in Netty. A remote attacker could exploit this vulnerability by sending specially crafted HTTP/2 or HTTP/3 Extended CONNECT requests. Netty's HTTP-object conversion path incorrectly processes these… |
| CVE-2026-93567 | Alta (7.5) | 0.75% | — | 18 sept 2026 | A flaw was found in Netty's HTTP/2 codec. When converting HTTP/1 CONNECT requests to HTTP/2, the component incorrectly uses the Host header instead of the CONNECT authority-form request-target for the tunnel authority.… |
| CVE-2026-93566 | Media (6.5) | 0.64% | — | 18 sept 2026 | A flaw was found in Netty. A remote attacker could exploit this by sending a specially crafted HTTP request that includes control characters within the chunk-size line. This bypasses the intended strict validation,… |
| CVE-2026-93565 | Alta (7.5) | 0.64% | — | 18 sept 2026 | A flaw was found in Netty RtspDecoder. The `RtspMethods.valueOf()` function incorrectly strips trailing control bytes from method tokens in Real-Time Streaming Protocol (RTSP) requests. A remote attacker can exploit… |
| CVE-2026-93564 | Alta (7.5) | 0.79% | — | 18 sept 2026 | A flaw was found in Netty. A reference-count leak in the HAProxy PROXY-v2 message decoder allows a remote, unauthenticated attacker to send specially crafted PROXY-protocol v2 headers. This can lead to memory… |
| CVE-2026-93558 | Alta (7.5) | 0.79% | — | 18 sept 2026 | A flaw was found in Netty's WebSocketServerExtensionHandler. A remote, unauthenticated attacker can exploit this vulnerability by using HTTP/1.1 pipelining to send requests faster than the application can respond. This… |
| CVE-2026-93560 | Alta (7.5) | 0.58% | — | 18 sept 2026 | A flaw was found in the Netty STOMP codec. A remote attacker could send a specially crafted STOMP frame with a content-length header exceeding the maximum integer value. This integer truncation vulnerability could lead… |
| CVE-2026-93492 | Media (5.3) | 0.64% | — | 18 sept 2026 | A flaw was found in Netty's HTTP/2 HpackEncoder. A remote attacker can exploit this by sending HTTP/2 SETTINGS frames with a very large MAX_HEADER_TABLE_SIZE. This causes the HpackEncoder to store an excessive number of… |
| CVE-2026-93491 | Alta (7.5) | 0.87% | — | 18 sept 2026 | A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipelining HTTP/1.1 requests on a single connection and withholding reads. This action causes the… |
| CVE-2026-93488 | Alta (7.5) | 0.70% | — | 18 sept 2026 | A flaw was found in Netty. SpdySessionHandler accepts an unlimited number of concurrent remote-initiated streams because localConcurrentStreams defaults to Integer.MAX_VALUE and the handler provides no API to change it.… |
| CVE-2026-93578 | Media (5.9) | 0.29% | — | 18 sept 2026 | A flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client. The client fails to verify the 'id-kp-OCSPSigning' Extended Key Usage (EKU) in OCSP responder certificates. A remote attacker, holding any… |
| CVE-2026-93575 | Alta (7.5) | 0.66% | — | 18 sept 2026 | A flaw was found in Netty's MqttDecoder. An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted MQTT CONNECT packet. The decoder fails to properly validate the 'Properties… |
| CVE-2026-93572 | Alta (7.5) | 0.58% | — | 18 sept 2026 | A flaw was found in Netty's `RedisArrayAggregator` component. A remote attacker can exploit this vulnerability by sending specially crafted nested Redis (RESP) array headers. This can cause the `RedisArrayAggregator` to… |
| CVE-2026-93563 | Alta (7.5) | 0.56% | — | 18 sept 2026 | A flaw was found in Netty's `SmtpResponseDecoder` component. A remote attacker, acting as a malicious or man-in-the-middle (MITM) SMTP server, could exploit this by sending a specially crafted, unbounded multi-line SMTP… |
| CVE-2026-93494 | Alta (7.5) | 0.58% | — | 18 sept 2026 | A flaw was found in Netty's StompSubframeDecoder component. A remote attacker can exploit this vulnerability by sending a specially crafted STOMP frame body without its terminating null byte. This causes the decoder to… |
| CVE-2026-89044 | Media (6.9) | 0.43% | — | 10 sept 2026 | Netty versions 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final fail to properly validate the final transfer coding in the Transfer-Encoding header, allowing attackers to smuggle requests by… |
| CVE-2026-76816 | Baja (3.5) | 0.27% | — | 24 ago 2026 | Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.137.Final and 4.2.17.Final, MqttEncoder does not validate client identifiers, will topics, usernames, and PUBLISH topic names… |
| CVE-2026-62380 | Media (6.3) | 0.44% | — | 22 ago 2026 | Netty (io.netty:netty-codec-socks) versions 4.2.0.Final through 4.2.16.Final and 4.1.x through 4.1.136.Final contain null byte, CRLF, and credential injection vulnerabilities in the SOCKS4 (Socks4ClientEncoder) and… |
| CVE-2026-75596 | Alta (8.7) | 0.69% | — | 19 ago 2026 | Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, the default io.netty.handler.ssl.SniHandler constructors use the pre-handshake ClientHello aggregation path… |
| CVE-2026-75595 | Crítica (9.1) | 0.46% | — | 19 ago 2026 | Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.handler.ssl.SslClientHelloHandler#decode checks the wrong offset before reading the four-byte TLS… |
| CVE-2026-59903 | Alta (7.5) | 0.25% | — | 17 ago 2026 | Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.http.cors.CorsHandler setVaryHeader replaces application Vary headers such as… |
| CVE-2026-59902 | Alta (7.5) | 0.67% | — | 17 ago 2026 | Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.sctp.SctpMessageCompletionHandler limits incomplete messages and fragment counts but… |
| CVE-2026-73508 | Alta (7.5) | 0.38% | — | 13 ago 2026 | Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.dns.AbstractDnsRecord,… |
| CVE-2026-73507 | Alta (7.5) | 0.79% | — | 13 ago 2026 | Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.xml.XmlFrameDecoder.decode() failed to preserve closing-tag parser state across… |
| CVE-2026-56818 | Media (6.5) | 0.47% | — | 7 ago 2026 | Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the RedisArrayAggregator Redis codec clears retained partial aggregate state when the maxNestedArrayDepth… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.