netty records
97 published records for vendor netty.
Researcher profile
- Entered KEV
- 1 · 1%
- Weaponized
- 1 · 1%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- 0 days
Recurring classes
- CWE-400 Uncontrolled Resource Consumption24
- CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')16
- CWE-770 Allocation of Resources Without Limits or Throttling10
- CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')6
- CWE-20 Improper Input Validation4
- CWE-401 Missing Release of Memory after Effective Lifetime3
The weakness classes this vendor ships most often: where to look.
CWEAll records
97 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
90Now | CVE-2023-44487Weaponized | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | High7.5 | KEV | 100.0% | Oct 10, 2023 |
40Plan | CVE-2019-20445No exploit | HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Trnetty · netty · CWE-444 | Critical9.1 | — | 13.5% | Jan 29, 2020 |
40Plan | CVE-2026-45674Proof of concept | Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Recordsnetty · netty · CWE-345 | Critical10.0 | — | 0.4% | Jun 12, 2026 |
40Plan | CVE-2026-47691No exploit | Netty has Insufficient Bailiwick Validation for NS Recordsnetty · netty · CWE-345 | Critical10.0 | — | 0.4% | Jun 12, 2026 |
39Monitor | CVE-2019-20444No exploit | HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header withnetty · netty · CWE-444 | Critical9.1 | — | 8.9% | Jan 29, 2020 |
39Monitor | CVE-2026-42581No exploit | Netty: HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitizationnetty · netty · CWE-444 | Critical9.8 | — | 0.7% | May 13, 2026 |
36Monitor | CVE-2026-42579No exploit | Netty: DNS Codec Input Validation Bypass in Netty (Encoder + Decoder)netty · netty · CWE-20 | Critical9.1 | — | 0.8% | May 13, 2026 |
36Monitor | CVE-2026-42584No exploit | Netty: HttpClientCodec response desynchronizationnetty · netty · CWE-444 | Critical9.1 | — | 0.7% | May 13, 2026 |
36Monitor | CVE-2026-75595No exploit | Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContextnetty · netty · CWE-754 | Critical9.1 | — | 0.5% | Aug 19, 2026 |
36Monitor | CVE-2026-56820No exploit | Netty: Missing CertificateID Validation in OCSP Response Allows Replay Attacksnetty · netty · CWE-295 | Critical9.1 | — | 0.3% | Jul 21, 2026 |
36Monitor | CVE-2024-36121No exploit | netty-incubator-codec-ohttp's BoringSSLAEADContext Repeats Noncesnetty · netty-incubator-codec-ohttp · CWE-190 | Critical9.1 | — | 0.3% | Jun 4, 2024 |
34Monitor | CVE-2026-33871No exploit | Netty HTTP/2 CONTINUATION Frame Flood DoS via Zero-Byte Frame Bypassnetty · netty · CWE-770 | High8.7 | — | 1.2% | Mar 27, 2026 |
34Monitor | CVE-2026-48059No exploit | Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustionnetty · netty · CWE-401 | High8.7 | — | 0.9% | Jun 12, 2026 |
34Monitor | CVE-2026-48006No exploit | Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregatornetty · netty · CWE-401 | High8.7 | — | 0.8% | Jun 12, 2026 |
34Monitor | CVE-2026-75596No exploit | Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsingnetty · netty · CWE-407 | High8.7 | — | 0.7% | Aug 19, 2026 |
34Monitor | CVE-2026-56745No exploit | Netty SpdyHttpDecoder: ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustionnetty · netty · CWE-400 | High8.7 | — | 0.6% | Jul 21, 2026 |
34Monitor | CVE-2026-55851No exploit | Netty codec-haproxy: Signed-Byte Sentinel Collision in HAProxyMessageDecoder Leads to Unbounded Memory Exhaustionnetty · netty · CWE-400 | High8.7 | — | 0.6% | Jul 21, 2026 |
34Monitor | CVE-2026-59901No exploit | Netty Bzip2Decoder: Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hangnetty · netty · CWE-835 | High8.7 | — | 0.5% | Jul 29, 2026 |
33Monitor | CVE-2016-4970No exploit | handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of netty · netty · CWE-835 | High7.5 | — | 11.3% | Apr 13, 2017 |
33Monitor | CVE-2020-11612No exploit | The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream.netty · netty · CWE-770 | High7.5 | — | 9.2% | Apr 7, 2020 |
33Monitor | CVE-2019-16869No exploit | Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leadsnetty · netty · CWE-444 | High7.5 | — | 8.4% | Sep 26, 2019 |
33Monitor | CVE-2026-56817No exploit | Netty: XML External Entity (XXE) injection via unconfigured XML factory when DTD and entity processing are enablednetty · netty · CWE-611 | High8.3 | — | 0.7% | Jul 21, 2026 |
32Monitor | CVE-2021-37137No exploit | The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage.netty · netty · CWE-400 | High7.5 | — | 6.6% | Oct 19, 2021 |
32Monitor | CVE-2021-37136No exploit | The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocatinetty · netty · CWE-400 | High7.5 | — | 5.9% | Oct 19, 2021 |
32Monitor | CVE-2015-2156No exploit | Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before netty · netty · CWE-20 | High7.5 | — | 5.2% | Oct 18, 2017 |
- CVE-2023-4448790Now
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
HighCVSS 7.5KEVWeaponizedEPSS 100%siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmwareOct 10, 2023
- CVE-2019-2044540Plan
HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Tr
CriticalCVSS 9.1No exploitEPSS 13%netty · nettyJan 29, 2020
- CVE-2026-4567440Plan
Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records
CriticalCVSS 10.0Proof of conceptEPSS 0%netty · nettyJun 12, 2026
- CVE-2026-4769140Plan
Netty has Insufficient Bailiwick Validation for NS Records
CriticalCVSS 10.0No exploitEPSS 0%netty · nettyJun 12, 2026
- CVE-2019-2044439Monitor
HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with
CriticalCVSS 9.1No exploitEPSS 9%netty · nettyJan 29, 2020
- CVE-2026-4258139Monitor
Netty: HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization
CriticalCVSS 9.8No exploitEPSS 1%netty · nettyMay 13, 2026
- CVE-2026-4257936Monitor
Netty: DNS Codec Input Validation Bypass in Netty (Encoder + Decoder)
CriticalCVSS 9.1No exploitEPSS 1%netty · nettyMay 13, 2026
- CVE-2026-4258436Monitor
Netty: HttpClientCodec response desynchronization
CriticalCVSS 9.1No exploitEPSS 1%netty · nettyMay 13, 2026
- CVE-2026-7559536Monitor
Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext
CriticalCVSS 9.1No exploitEPSS 0%netty · nettyAug 19, 2026
- CVE-2026-5682036Monitor
Netty: Missing CertificateID Validation in OCSP Response Allows Replay Attacks
CriticalCVSS 9.1No exploitEPSS 0%netty · nettyJul 21, 2026
- CVE-2024-3612136Monitor
netty-incubator-codec-ohttp's BoringSSLAEADContext Repeats Nonces
CriticalCVSS 9.1No exploitEPSS 0%netty · netty-incubator-codec-ohttpJun 4, 2024
- CVE-2026-3387134Monitor
Netty HTTP/2 CONTINUATION Frame Flood DoS via Zero-Byte Frame Bypass
HighCVSS 8.7No exploitEPSS 1%netty · nettyMar 27, 2026
- CVE-2026-4805934Monitor
Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion
HighCVSS 8.7No exploitEPSS 1%netty · nettyJun 12, 2026
- CVE-2026-4800634Monitor
Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator
HighCVSS 8.7No exploitEPSS 1%netty · nettyJun 12, 2026
- CVE-2026-7559634Monitor
Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing
HighCVSS 8.7No exploitEPSS 1%netty · nettyAug 19, 2026
- CVE-2026-5674534Monitor
Netty SpdyHttpDecoder: ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustion
HighCVSS 8.7No exploitEPSS 1%netty · nettyJul 21, 2026
- CVE-2026-5585134Monitor
Netty codec-haproxy: Signed-Byte Sentinel Collision in HAProxyMessageDecoder Leads to Unbounded Memory Exhaustion
HighCVSS 8.7No exploitEPSS 1%netty · nettyJul 21, 2026
- CVE-2026-5990134Monitor
Netty Bzip2Decoder: Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang
HighCVSS 8.7No exploitEPSS 0%netty · nettyJul 29, 2026
- CVE-2016-497033Monitor
handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of
HighCVSS 7.5No exploitEPSS 11%netty · nettyApr 13, 2017
- CVE-2020-1161233Monitor
The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream.
HighCVSS 7.5No exploitEPSS 9%netty · nettyApr 7, 2020
- CVE-2019-1686933Monitor
Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads
HighCVSS 7.5No exploitEPSS 8%netty · nettySep 26, 2019
- CVE-2026-5681733Monitor
Netty: XML External Entity (XXE) injection via unconfigured XML factory when DTD and entity processing are enabled
HighCVSS 8.3No exploitEPSS 1%netty · nettyJul 21, 2026
- CVE-2021-3713732Monitor
The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage.
HighCVSS 7.5No exploitEPSS 7%netty · nettyOct 19, 2021
- CVE-2021-3713632Monitor
The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocati
HighCVSS 7.5No exploitEPSS 6%netty · nettyOct 19, 2021
- CVE-2015-215632Monitor
Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before
HighCVSS 7.5No exploitEPSS 5%netty · nettyOct 18, 2017