CWE-1035 · 13 записей
OWASP Top Ten 2017 Category A9 - Using Components with Known Vulnerabilities
CVE этого класса
13 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
30Наблюдать | CVE-2026-93558Эксплойта нет | Io.netty/netty-codec-http: netty: unbounded per-connection queue growth in websocketserverextensionhandler leads to denial of servicered hat · red hat amq broker 7 · CWE-1035 | Высокая7,5 | — | 1,0 % | 18 сент. 2026 г. |
30Наблюдать | CVE-2026-93564Эксплойта нет | Io.netty/netty-codec-haproxy: netty: haproxy proxy-v2 nested-tlv grandchild bytebuf reference-count leak (incomplete fix of pr #16881)red hat · red hat amq broker 7 · CWE-1035 | Высокая7,5 | — | 0,9 % | 18 сент. 2026 г. |
30Наблюдать | CVE-2026-93565Эксплойта нет | Io.netty/netty-codec-http: netty rtspdecoder method-token smuggling via trailing control bytered hat · red hat amq broker 7 · CWE-1035 | Высокая7,5 | — | 0,7 % | 18 сент. 2026 г. |
30Наблюдать | CVE-2026-93560Эксплойта нет | Io.netty/netty-codec-stomp: netty: stomp codec content-length long-to-int truncation causes infinite decode loop dosred hat · red hat build of apache camel for spring boot 4 · CWE-1035 | Высокая7,5 | — | 0,4 % | 18 сент. 2026 г. |
30Наблюдать | CVE-2026-93494Эксплойта нет | Io.netty/netty-codec-stomp: netty: bytebuf leak in stompsubframedecoder when a frame body is never terminatedred hat · red hat build of apache camel for spring boot 4 · CWE-1035 | Высокая7,5 | — | 0,4 % | 18 сент. 2026 г. |
30Наблюдать | CVE-2026-93575Эксплойта нет | Io.netty/netty-codec-mqtt: netty: resource exhaustion in mqttdecoderred hat · red hat amq broker 7 · CWE-1035 | Высокая7,5 | — | 0,4 % | 18 сент. 2026 г. |
30Наблюдать | CVE-2026-93563Эксплойта нет | Io.netty/netty-codec-smtp: netty: unbounded multi-line response accumulation in smtpresponsedecoder leads to memory-exhaustion dosred hat · red hat build of apache camel for spring boot 4 · CWE-1035 | Высокая7,5 | — | 0,3 % | 18 сент. 2026 г. |
26Наблюдать | CVE-2026-93579Эксплойта нет | Io.netty/netty-codec-http2: netty: http/2 header field values are not validated by default (cr/lf/nul passthrough)red hat · red hat amq broker 7 · CWE-1035 | Средняя6,5 | — | 0,9 % | 18 сент. 2026 г. |
26Наблюдать | CVE-2026-93566Эксплойта нет | Io.netty/netty-codec-http: netty: http request smuggling due to control characters in the chunk-size linered hat · red hat amq broker 7 · CWE-1035 | Средняя6,5 | — | 0,5 % | 18 сент. 2026 г. |
26Наблюдать | CVE-2026-93562Эксплойта нет | Io.netty/netty-codec-http: netty: incomplete validation of malformed transfer-encoding allows http request smugglingred hat · red hat amq broker 7 · CWE-1035 | Средняя6,5 | — | 0,4 % | 18 сент. 2026 г. |
26Наблюдать | CVE-2026-93561Эксплойта нет | Io.netty/netty-codec-memcache: netty: memcache binary codec signed/unsigned type mismatch causes frame desynchronization and response smugglingred hat · red hat build of apache camel for spring boot 4 · CWE-1035 | Средняя6,5 | — | 0,3 % | 18 сент. 2026 г. |
23Наблюдать | CVE-2026-93578Эксплойта нет | Io.netty/netty-handler-ssl-ocsp: netty: missing extended key usage (eku) check in ocsp client allows certificate revocation bypassred hat · red hat build of apache camel for spring boot 4 · CWE-1035 | Средняя5,9 | — | 0,2 % | 18 сент. 2026 г. |
21Наблюдать | CVE-2026-93492Эксплойта нет | Io.netty/netty-codec-http2: netty: http/2 hpackencoder dos with large table sizered hat · red hat amq broker 7 · CWE-1035 | Средняя5,3 | — | 0,4 % | 18 сент. 2026 г. |
- CVE-2026-9355830Наблюдать
Io.netty/netty-codec-http: netty: unbounded per-connection queue growth in websocketserverextensionhandler leads to denial of service
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %red hat · red hat amq broker 718 сент. 2026 г.
- CVE-2026-9356430Наблюдать
Io.netty/netty-codec-haproxy: netty: haproxy proxy-v2 nested-tlv grandchild bytebuf reference-count leak (incomplete fix of pr #16881)
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %red hat · red hat amq broker 718 сент. 2026 г.
- CVE-2026-9356530Наблюдать
Io.netty/netty-codec-http: netty rtspdecoder method-token smuggling via trailing control byte
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %red hat · red hat amq broker 718 сент. 2026 г.
- CVE-2026-9356030Наблюдать
Io.netty/netty-codec-stomp: netty: stomp codec content-length long-to-int truncation causes infinite decode loop dos
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %red hat · red hat build of apache camel for spring boot 418 сент. 2026 г.
- CVE-2026-9349430Наблюдать
Io.netty/netty-codec-stomp: netty: bytebuf leak in stompsubframedecoder when a frame body is never terminated
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %red hat · red hat build of apache camel for spring boot 418 сент. 2026 г.
- CVE-2026-9357530Наблюдать
Io.netty/netty-codec-mqtt: netty: resource exhaustion in mqttdecoder
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %red hat · red hat amq broker 718 сент. 2026 г.
- CVE-2026-9356330Наблюдать
Io.netty/netty-codec-smtp: netty: unbounded multi-line response accumulation in smtpresponsedecoder leads to memory-exhaustion dos
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %red hat · red hat build of apache camel for spring boot 418 сент. 2026 г.
- CVE-2026-9357926Наблюдать
Io.netty/netty-codec-http2: netty: http/2 header field values are not validated by default (cr/lf/nul passthrough)
СредняяCVSS 6,5Эксплойта нетEPSS 1 %red hat · red hat amq broker 718 сент. 2026 г.
- CVE-2026-9356626Наблюдать
Io.netty/netty-codec-http: netty: http request smuggling due to control characters in the chunk-size line
СредняяCVSS 6,5Эксплойта нетEPSS 0 %red hat · red hat amq broker 718 сент. 2026 г.
- CVE-2026-9356226Наблюдать
Io.netty/netty-codec-http: netty: incomplete validation of malformed transfer-encoding allows http request smuggling
СредняяCVSS 6,5Эксплойта нетEPSS 0 %red hat · red hat amq broker 718 сент. 2026 г.
- CVE-2026-9356126Наблюдать
Io.netty/netty-codec-memcache: netty: memcache binary codec signed/unsigned type mismatch causes frame desynchronization and response smuggling
СредняяCVSS 6,5Эксплойта нетEPSS 0 %red hat · red hat build of apache camel for spring boot 418 сент. 2026 г.
- CVE-2026-9357823Наблюдать
Io.netty/netty-handler-ssl-ocsp: netty: missing extended key usage (eku) check in ocsp client allows certificate revocation bypass
СредняяCVSS 5,9Эксплойта нетEPSS 0 %red hat · red hat build of apache camel for spring boot 418 сент. 2026 г.
- CVE-2026-9349221Наблюдать
Io.netty/netty-codec-http2: netty: http/2 hpackencoder dos with large table size
СредняяCVSS 5,3Эксплойта нетEPSS 0 %red hat · red hat amq broker 718 сент. 2026 г.