Skip to content
Noroxi

CWE-1035 · 13 records

OWASP Top Ten 2017 Category A9 - Using Components with Known Vulnerabilities

CVEs in this class

13 records

  • Io.netty/netty-codec-http: netty: unbounded per-connection queue growth in websocketserverextensionhandler leads to denial of service

    HighCVSS 7.5No exploitEPSS 1%

    red hat · red hat amq broker 7Sep 18, 2026

  • Io.netty/netty-codec-haproxy: netty: haproxy proxy-v2 nested-tlv grandchild bytebuf reference-count leak (incomplete fix of pr #16881)

    HighCVSS 7.5No exploitEPSS 1%

    red hat · red hat amq broker 7Sep 18, 2026

  • Io.netty/netty-codec-http: netty rtspdecoder method-token smuggling via trailing control byte

    HighCVSS 7.5No exploitEPSS 1%

    red hat · red hat amq broker 7Sep 18, 2026

  • Io.netty/netty-codec-stomp: netty: stomp codec content-length long-to-int truncation causes infinite decode loop dos

    HighCVSS 7.5No exploitEPSS 0%

    red hat · red hat build of apache camel for spring boot 4Sep 18, 2026

  • Io.netty/netty-codec-stomp: netty: bytebuf leak in stompsubframedecoder when a frame body is never terminated

    HighCVSS 7.5No exploitEPSS 0%

    red hat · red hat build of apache camel for spring boot 4Sep 18, 2026

  • Io.netty/netty-codec-mqtt: netty: resource exhaustion in mqttdecoder

    HighCVSS 7.5No exploitEPSS 0%

    red hat · red hat amq broker 7Sep 18, 2026

  • Io.netty/netty-codec-smtp: netty: unbounded multi-line response accumulation in smtpresponsedecoder leads to memory-exhaustion dos

    HighCVSS 7.5No exploitEPSS 0%

    red hat · red hat build of apache camel for spring boot 4Sep 18, 2026

  • Io.netty/netty-codec-http2: netty: http/2 header field values are not validated by default (cr/lf/nul passthrough)

    MediumCVSS 6.5No exploitEPSS 1%

    red hat · red hat amq broker 7Sep 18, 2026

  • Io.netty/netty-codec-http: netty: http request smuggling due to control characters in the chunk-size line

    MediumCVSS 6.5No exploitEPSS 0%

    red hat · red hat amq broker 7Sep 18, 2026

  • Io.netty/netty-codec-http: netty: incomplete validation of malformed transfer-encoding allows http request smuggling

    MediumCVSS 6.5No exploitEPSS 0%

    red hat · red hat amq broker 7Sep 18, 2026

  • Io.netty/netty-codec-memcache: netty: memcache binary codec signed/unsigned type mismatch causes frame desynchronization and response smuggling

    MediumCVSS 6.5No exploitEPSS 0%

    red hat · red hat build of apache camel for spring boot 4Sep 18, 2026

  • Io.netty/netty-handler-ssl-ocsp: netty: missing extended key usage (eku) check in ocsp client allows certificate revocation bypass

    MediumCVSS 5.9No exploitEPSS 0%

    red hat · red hat build of apache camel for spring boot 4Sep 18, 2026

  • Io.netty/netty-codec-http2: netty: http/2 hpackencoder dos with large table size

    MediumCVSS 5.3No exploitEPSS 0%

    red hat · red hat amq broker 7Sep 18, 2026

All vulnerability classes