CWE-1035 · 13 records
OWASP Top Ten 2017 Category A9 - Using Components with Known Vulnerabilities
CVEs in this class
13 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
30Monitor | CVE-2026-93558No exploit | Io.netty/netty-codec-http: netty: unbounded per-connection queue growth in websocketserverextensionhandler leads to denial of servicered hat · red hat amq broker 7 · CWE-1035 | High7.5 | — | 1.0% | Sep 18, 2026 |
30Monitor | CVE-2026-93564No exploit | Io.netty/netty-codec-haproxy: netty: haproxy proxy-v2 nested-tlv grandchild bytebuf reference-count leak (incomplete fix of pr #16881)red hat · red hat amq broker 7 · CWE-1035 | High7.5 | — | 0.9% | Sep 18, 2026 |
30Monitor | CVE-2026-93565No exploit | Io.netty/netty-codec-http: netty rtspdecoder method-token smuggling via trailing control bytered hat · red hat amq broker 7 · CWE-1035 | High7.5 | — | 0.7% | Sep 18, 2026 |
30Monitor | CVE-2026-93560No exploit | Io.netty/netty-codec-stomp: netty: stomp codec content-length long-to-int truncation causes infinite decode loop dosred hat · red hat build of apache camel for spring boot 4 · CWE-1035 | High7.5 | — | 0.4% | Sep 18, 2026 |
30Monitor | CVE-2026-93494No exploit | Io.netty/netty-codec-stomp: netty: bytebuf leak in stompsubframedecoder when a frame body is never terminatedred hat · red hat build of apache camel for spring boot 4 · CWE-1035 | High7.5 | — | 0.4% | Sep 18, 2026 |
30Monitor | CVE-2026-93575No exploit | Io.netty/netty-codec-mqtt: netty: resource exhaustion in mqttdecoderred hat · red hat amq broker 7 · CWE-1035 | High7.5 | — | 0.4% | Sep 18, 2026 |
30Monitor | CVE-2026-93563No exploit | Io.netty/netty-codec-smtp: netty: unbounded multi-line response accumulation in smtpresponsedecoder leads to memory-exhaustion dosred hat · red hat build of apache camel for spring boot 4 · CWE-1035 | High7.5 | — | 0.3% | Sep 18, 2026 |
26Monitor | CVE-2026-93579No exploit | Io.netty/netty-codec-http2: netty: http/2 header field values are not validated by default (cr/lf/nul passthrough)red hat · red hat amq broker 7 · CWE-1035 | Medium6.5 | — | 0.9% | Sep 18, 2026 |
26Monitor | CVE-2026-93566No exploit | Io.netty/netty-codec-http: netty: http request smuggling due to control characters in the chunk-size linered hat · red hat amq broker 7 · CWE-1035 | Medium6.5 | — | 0.5% | Sep 18, 2026 |
26Monitor | CVE-2026-93562No exploit | Io.netty/netty-codec-http: netty: incomplete validation of malformed transfer-encoding allows http request smugglingred hat · red hat amq broker 7 · CWE-1035 | Medium6.5 | — | 0.4% | Sep 18, 2026 |
26Monitor | CVE-2026-93561No exploit | Io.netty/netty-codec-memcache: netty: memcache binary codec signed/unsigned type mismatch causes frame desynchronization and response smugglingred hat · red hat build of apache camel for spring boot 4 · CWE-1035 | Medium6.5 | — | 0.3% | Sep 18, 2026 |
23Monitor | CVE-2026-93578No exploit | Io.netty/netty-handler-ssl-ocsp: netty: missing extended key usage (eku) check in ocsp client allows certificate revocation bypassred hat · red hat build of apache camel for spring boot 4 · CWE-1035 | Medium5.9 | — | 0.2% | Sep 18, 2026 |
21Monitor | CVE-2026-93492No exploit | Io.netty/netty-codec-http2: netty: http/2 hpackencoder dos with large table sizered hat · red hat amq broker 7 · CWE-1035 | Medium5.3 | — | 0.4% | Sep 18, 2026 |
- CVE-2026-9355830Monitor
Io.netty/netty-codec-http: netty: unbounded per-connection queue growth in websocketserverextensionhandler leads to denial of service
HighCVSS 7.5No exploitEPSS 1%red hat · red hat amq broker 7Sep 18, 2026
- CVE-2026-9356430Monitor
Io.netty/netty-codec-haproxy: netty: haproxy proxy-v2 nested-tlv grandchild bytebuf reference-count leak (incomplete fix of pr #16881)
HighCVSS 7.5No exploitEPSS 1%red hat · red hat amq broker 7Sep 18, 2026
- CVE-2026-9356530Monitor
Io.netty/netty-codec-http: netty rtspdecoder method-token smuggling via trailing control byte
HighCVSS 7.5No exploitEPSS 1%red hat · red hat amq broker 7Sep 18, 2026
- CVE-2026-9356030Monitor
Io.netty/netty-codec-stomp: netty: stomp codec content-length long-to-int truncation causes infinite decode loop dos
HighCVSS 7.5No exploitEPSS 0%red hat · red hat build of apache camel for spring boot 4Sep 18, 2026
- CVE-2026-9349430Monitor
Io.netty/netty-codec-stomp: netty: bytebuf leak in stompsubframedecoder when a frame body is never terminated
HighCVSS 7.5No exploitEPSS 0%red hat · red hat build of apache camel for spring boot 4Sep 18, 2026
- CVE-2026-9357530Monitor
Io.netty/netty-codec-mqtt: netty: resource exhaustion in mqttdecoder
HighCVSS 7.5No exploitEPSS 0%red hat · red hat amq broker 7Sep 18, 2026
- CVE-2026-9356330Monitor
Io.netty/netty-codec-smtp: netty: unbounded multi-line response accumulation in smtpresponsedecoder leads to memory-exhaustion dos
HighCVSS 7.5No exploitEPSS 0%red hat · red hat build of apache camel for spring boot 4Sep 18, 2026
- CVE-2026-9357926Monitor
Io.netty/netty-codec-http2: netty: http/2 header field values are not validated by default (cr/lf/nul passthrough)
MediumCVSS 6.5No exploitEPSS 1%red hat · red hat amq broker 7Sep 18, 2026
- CVE-2026-9356626Monitor
Io.netty/netty-codec-http: netty: http request smuggling due to control characters in the chunk-size line
MediumCVSS 6.5No exploitEPSS 0%red hat · red hat amq broker 7Sep 18, 2026
- CVE-2026-9356226Monitor
Io.netty/netty-codec-http: netty: incomplete validation of malformed transfer-encoding allows http request smuggling
MediumCVSS 6.5No exploitEPSS 0%red hat · red hat amq broker 7Sep 18, 2026
- CVE-2026-9356126Monitor
Io.netty/netty-codec-memcache: netty: memcache binary codec signed/unsigned type mismatch causes frame desynchronization and response smuggling
MediumCVSS 6.5No exploitEPSS 0%red hat · red hat build of apache camel for spring boot 4Sep 18, 2026
- CVE-2026-9357823Monitor
Io.netty/netty-handler-ssl-ocsp: netty: missing extended key usage (eku) check in ocsp client allows certificate revocation bypass
MediumCVSS 5.9No exploitEPSS 0%red hat · red hat build of apache camel for spring boot 4Sep 18, 2026
- CVE-2026-9349221Monitor
Io.netty/netty-codec-http2: netty: http/2 hpackencoder dos with large table size
MediumCVSS 5.3No exploitEPSS 0%red hat · red hat amq broker 7Sep 18, 2026