Записи netty
97 опубликованных записей вендора netty.
Профиль для исследователя
- Попали в KEV
- 1 · 1 %
- С эксплойтом
- 1 · 1 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- 0 дн.
Повторяющиеся классы
- CWE-400 Uncontrolled Resource Consumption24
- CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')16
- CWE-770 Allocation of Resources Without Limits or Throttling10
- CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')6
- CWE-20 Improper Input Validation4
- CWE-401 Missing Release of Memory after Effective Lifetime3
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
97 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
90Срочно | CVE-2023-44487Готовый эксплойт | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | Высокая7,5 | KEV | 100,0 % | 10 окт. 2023 г. |
40В плане | CVE-2019-20445Эксплойта нет | HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Trnetty · netty · CWE-444 | Критическая9,1 | — | 13,5 % | 29 янв. 2020 г. |
40В плане | CVE-2026-45674Proof of concept | Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Recordsnetty · netty · CWE-345 | Критическая10,0 | — | 0,4 % | 12 июн. 2026 г. |
40В плане | CVE-2026-47691Эксплойта нет | Netty has Insufficient Bailiwick Validation for NS Recordsnetty · netty · CWE-345 | Критическая10,0 | — | 0,4 % | 12 июн. 2026 г. |
39Наблюдать | CVE-2019-20444Эксплойта нет | HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header withnetty · netty · CWE-444 | Критическая9,1 | — | 8,9 % | 29 янв. 2020 г. |
39Наблюдать | CVE-2026-42581Эксплойта нет | Netty: HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitizationnetty · netty · CWE-444 | Критическая9,8 | — | 0,7 % | 13 мая 2026 г. |
36Наблюдать | CVE-2026-42579Эксплойта нет | Netty: DNS Codec Input Validation Bypass in Netty (Encoder + Decoder)netty · netty · CWE-20 | Критическая9,1 | — | 0,8 % | 13 мая 2026 г. |
36Наблюдать | CVE-2026-42584Эксплойта нет | Netty: HttpClientCodec response desynchronizationnetty · netty · CWE-444 | Критическая9,1 | — | 0,7 % | 13 мая 2026 г. |
36Наблюдать | CVE-2026-75595Эксплойта нет | Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContextnetty · netty · CWE-754 | Критическая9,1 | — | 0,5 % | 19 авг. 2026 г. |
36Наблюдать | CVE-2026-56820Эксплойта нет | Netty: Missing CertificateID Validation in OCSP Response Allows Replay Attacksnetty · netty · CWE-295 | Критическая9,1 | — | 0,3 % | 21 июл. 2026 г. |
36Наблюдать | CVE-2024-36121Эксплойта нет | netty-incubator-codec-ohttp's BoringSSLAEADContext Repeats Noncesnetty · netty-incubator-codec-ohttp · CWE-190 | Критическая9,1 | — | 0,3 % | 4 июн. 2024 г. |
34Наблюдать | CVE-2026-33871Эксплойта нет | Netty HTTP/2 CONTINUATION Frame Flood DoS via Zero-Byte Frame Bypassnetty · netty · CWE-770 | Высокая8,7 | — | 1,2 % | 27 мар. 2026 г. |
34Наблюдать | CVE-2026-48059Эксплойта нет | Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustionnetty · netty · CWE-401 | Высокая8,7 | — | 0,9 % | 12 июн. 2026 г. |
34Наблюдать | CVE-2026-48006Эксплойта нет | Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregatornetty · netty · CWE-401 | Высокая8,7 | — | 0,8 % | 12 июн. 2026 г. |
34Наблюдать | CVE-2026-75596Эксплойта нет | Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsingnetty · netty · CWE-407 | Высокая8,7 | — | 0,7 % | 19 авг. 2026 г. |
34Наблюдать | CVE-2026-56745Эксплойта нет | Netty SpdyHttpDecoder: ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustionnetty · netty · CWE-400 | Высокая8,7 | — | 0,6 % | 21 июл. 2026 г. |
34Наблюдать | CVE-2026-55851Эксплойта нет | Netty codec-haproxy: Signed-Byte Sentinel Collision in HAProxyMessageDecoder Leads to Unbounded Memory Exhaustionnetty · netty · CWE-400 | Высокая8,7 | — | 0,6 % | 21 июл. 2026 г. |
34Наблюдать | CVE-2026-59901Эксплойта нет | Netty Bzip2Decoder: Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hangnetty · netty · CWE-835 | Высокая8,7 | — | 0,5 % | 29 июл. 2026 г. |
33Наблюдать | CVE-2016-4970Эксплойта нет | handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of netty · netty · CWE-835 | Высокая7,5 | — | 11,3 % | 13 апр. 2017 г. |
33Наблюдать | CVE-2020-11612Эксплойта нет | The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream.netty · netty · CWE-770 | Высокая7,5 | — | 9,2 % | 7 апр. 2020 г. |
33Наблюдать | CVE-2019-16869Эксплойта нет | Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leadsnetty · netty · CWE-444 | Высокая7,5 | — | 8,4 % | 26 сент. 2019 г. |
33Наблюдать | CVE-2026-56817Эксплойта нет | Netty: XML External Entity (XXE) injection via unconfigured XML factory when DTD and entity processing are enablednetty · netty · CWE-611 | Высокая8,3 | — | 0,7 % | 21 июл. 2026 г. |
32Наблюдать | CVE-2021-37137Эксплойта нет | The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage.netty · netty · CWE-400 | Высокая7,5 | — | 6,6 % | 19 окт. 2021 г. |
32Наблюдать | CVE-2021-37136Эксплойта нет | The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocatinetty · netty · CWE-400 | Высокая7,5 | — | 5,9 % | 19 окт. 2021 г. |
32Наблюдать | CVE-2015-2156Эксплойта нет | Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before netty · netty · CWE-20 | Высокая7,5 | — | 5,2 % | 18 окт. 2017 г. |
- CVE-2023-4448790Срочно
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware10 окт. 2023 г.
- CVE-2019-2044540В плане
HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Tr
КритическаяCVSS 9,1Эксплойта нетEPSS 13 %netty · netty29 янв. 2020 г.
- CVE-2026-4567440В плане
Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records
КритическаяCVSS 10,0Proof of conceptEPSS 0 %netty · netty12 июн. 2026 г.
- CVE-2026-4769140В плане
Netty has Insufficient Bailiwick Validation for NS Records
КритическаяCVSS 10,0Эксплойта нетEPSS 0 %netty · netty12 июн. 2026 г.
- CVE-2019-2044439Наблюдать
HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with
КритическаяCVSS 9,1Эксплойта нетEPSS 9 %netty · netty29 янв. 2020 г.
- CVE-2026-4258139Наблюдать
Netty: HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %netty · netty13 мая 2026 г.
- CVE-2026-4257936Наблюдать
Netty: DNS Codec Input Validation Bypass in Netty (Encoder + Decoder)
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %netty · netty13 мая 2026 г.
- CVE-2026-4258436Наблюдать
Netty: HttpClientCodec response desynchronization
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %netty · netty13 мая 2026 г.
- CVE-2026-7559536Наблюдать
Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %netty · netty19 авг. 2026 г.
- CVE-2026-5682036Наблюдать
Netty: Missing CertificateID Validation in OCSP Response Allows Replay Attacks
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %netty · netty21 июл. 2026 г.
- CVE-2024-3612136Наблюдать
netty-incubator-codec-ohttp's BoringSSLAEADContext Repeats Nonces
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %netty · netty-incubator-codec-ohttp4 июн. 2024 г.
- CVE-2026-3387134Наблюдать
Netty HTTP/2 CONTINUATION Frame Flood DoS via Zero-Byte Frame Bypass
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %netty · netty27 мар. 2026 г.
- CVE-2026-4805934Наблюдать
Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %netty · netty12 июн. 2026 г.
- CVE-2026-4800634Наблюдать
Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %netty · netty12 июн. 2026 г.
- CVE-2026-7559634Наблюдать
Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %netty · netty19 авг. 2026 г.
- CVE-2026-5674534Наблюдать
Netty SpdyHttpDecoder: ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustion
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %netty · netty21 июл. 2026 г.
- CVE-2026-5585134Наблюдать
Netty codec-haproxy: Signed-Byte Sentinel Collision in HAProxyMessageDecoder Leads to Unbounded Memory Exhaustion
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %netty · netty21 июл. 2026 г.
- CVE-2026-5990134Наблюдать
Netty Bzip2Decoder: Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %netty · netty29 июл. 2026 г.
- CVE-2016-497033Наблюдать
handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of
ВысокаяCVSS 7,5Эксплойта нетEPSS 11 %netty · netty13 апр. 2017 г.
- CVE-2020-1161233Наблюдать
The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream.
ВысокаяCVSS 7,5Эксплойта нетEPSS 9 %netty · netty7 апр. 2020 г.
- CVE-2019-1686933Наблюдать
Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads
ВысокаяCVSS 7,5Эксплойта нетEPSS 8 %netty · netty26 сент. 2019 г.
- CVE-2026-5681733Наблюдать
Netty: XML External Entity (XXE) injection via unconfigured XML factory when DTD and entity processing are enabled
ВысокаяCVSS 8,3Эксплойта нетEPSS 1 %netty · netty21 июл. 2026 г.
- CVE-2021-3713732Наблюдать
The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage.
ВысокаяCVSS 7,5Эксплойта нетEPSS 7 %netty · netty19 окт. 2021 г.
- CVE-2021-3713632Наблюдать
The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocati
ВысокаяCVSS 7,5Эксплойта нетEPSS 6 %netty · netty19 окт. 2021 г.
- CVE-2015-215632Наблюдать
Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %netty · netty18 окт. 2017 г.