Skip to content
Noroxi

netty records

97 published records for vendor netty.

All records

97 records
  • The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as

    HighCVSS 7.5KEVWeaponizedEPSS 100%

    siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmwareOct 10, 2023

  • HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Tr

    CriticalCVSS 9.1No exploitEPSS 13%

    netty · nettyJan 29, 2020

  • Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records

    CriticalCVSS 10.0Proof of conceptEPSS 0%

    netty · nettyJun 12, 2026

  • Netty has Insufficient Bailiwick Validation for NS Records

    CriticalCVSS 10.0No exploitEPSS 0%

    netty · nettyJun 12, 2026

  • HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with

    CriticalCVSS 9.1No exploitEPSS 9%

    netty · nettyJan 29, 2020

  • Netty: HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization

    CriticalCVSS 9.8No exploitEPSS 1%

    netty · nettyMay 13, 2026

  • Netty: DNS Codec Input Validation Bypass in Netty (Encoder + Decoder)

    CriticalCVSS 9.1No exploitEPSS 1%

    netty · nettyMay 13, 2026

  • Netty: HttpClientCodec response desynchronization

    CriticalCVSS 9.1No exploitEPSS 1%

    netty · nettyMay 13, 2026

  • Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext

    CriticalCVSS 9.1No exploitEPSS 0%

    netty · nettyAug 19, 2026

  • Netty: Missing CertificateID Validation in OCSP Response Allows Replay Attacks

    CriticalCVSS 9.1No exploitEPSS 0%

    netty · nettyJul 21, 2026

  • netty-incubator-codec-ohttp's BoringSSLAEADContext Repeats Nonces

    CriticalCVSS 9.1No exploitEPSS 0%

    netty · netty-incubator-codec-ohttpJun 4, 2024

  • Netty HTTP/2 CONTINUATION Frame Flood DoS via Zero-Byte Frame Bypass

    HighCVSS 8.7No exploitEPSS 1%

    netty · nettyMar 27, 2026

  • Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion

    HighCVSS 8.7No exploitEPSS 1%

    netty · nettyJun 12, 2026

  • Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator

    HighCVSS 8.7No exploitEPSS 1%

    netty · nettyJun 12, 2026

  • Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing

    HighCVSS 8.7No exploitEPSS 1%

    netty · nettyAug 19, 2026

  • Netty SpdyHttpDecoder: ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustion

    HighCVSS 8.7No exploitEPSS 1%

    netty · nettyJul 21, 2026

  • Netty codec-haproxy: Signed-Byte Sentinel Collision in HAProxyMessageDecoder Leads to Unbounded Memory Exhaustion

    HighCVSS 8.7No exploitEPSS 1%

    netty · nettyJul 21, 2026

  • Netty Bzip2Decoder: Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang

    HighCVSS 8.7No exploitEPSS 0%

    netty · nettyJul 29, 2026

  • CVE-2016-4970
    33Monitor

    handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of

    HighCVSS 7.5No exploitEPSS 11%

    netty · nettyApr 13, 2017

  • The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream.

    HighCVSS 7.5No exploitEPSS 9%

    netty · nettyApr 7, 2020

  • Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads

    HighCVSS 7.5No exploitEPSS 8%

    netty · nettySep 26, 2019

  • Netty: XML External Entity (XXE) injection via unconfigured XML factory when DTD and entity processing are enabled

    HighCVSS 8.3No exploitEPSS 1%

    netty · nettyJul 21, 2026

  • The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage.

    HighCVSS 7.5No exploitEPSS 7%

    netty · nettyOct 19, 2021

  • The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocati

    HighCVSS 7.5No exploitEPSS 6%

    netty · nettyOct 19, 2021

  • CVE-2015-2156
    32Monitor

    Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before

    HighCVSS 7.5No exploitEPSS 5%

    netty · nettyOct 18, 2017