netty kayıtları
netty üreticisine ait 97 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %1
- Silahlaştırılmış
- 1 · %1
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- 0 gün
Tekrar eden sınıflar
- CWE-400 Uncontrolled Resource Consumption24
- CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')16
- CWE-770 Allocation of Resources Without Limits or Throttling10
- CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')6
- CWE-20 Improper Input Validation4
- CWE-401 Missing Release of Memory after Effective Lifetime3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
97 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
90Hemen | CVE-2023-44487Silahlaştırılmış | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | Yüksek7,5 | KEV | %100,0 | 10 Eki 2023 |
40Planlayın | CVE-2019-20445İstismar yok | HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Trnetty · netty · CWE-444 | Kritik9,1 | — | %13,5 | 29 Oca 2020 |
40Planlayın | CVE-2026-45674Kavram kanıtı | Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Recordsnetty · netty · CWE-345 | Kritik10,0 | — | %0,4 | 12 Haz 2026 |
40Planlayın | CVE-2026-47691İstismar yok | Netty has Insufficient Bailiwick Validation for NS Recordsnetty · netty · CWE-345 | Kritik10,0 | — | %0,4 | 12 Haz 2026 |
39İzleyin | CVE-2019-20444İstismar yok | HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header withnetty · netty · CWE-444 | Kritik9,1 | — | %8,9 | 29 Oca 2020 |
39İzleyin | CVE-2026-42581İstismar yok | Netty: HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitizationnetty · netty · CWE-444 | Kritik9,8 | — | %0,7 | 13 May 2026 |
36İzleyin | CVE-2026-42579İstismar yok | Netty: DNS Codec Input Validation Bypass in Netty (Encoder + Decoder)netty · netty · CWE-20 | Kritik9,1 | — | %0,8 | 13 May 2026 |
36İzleyin | CVE-2026-42584İstismar yok | Netty: HttpClientCodec response desynchronizationnetty · netty · CWE-444 | Kritik9,1 | — | %0,7 | 13 May 2026 |
36İzleyin | CVE-2026-75595İstismar yok | Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContextnetty · netty · CWE-754 | Kritik9,1 | — | %0,5 | 19 Ağu 2026 |
36İzleyin | CVE-2026-56820İstismar yok | Netty: Missing CertificateID Validation in OCSP Response Allows Replay Attacksnetty · netty · CWE-295 | Kritik9,1 | — | %0,3 | 21 Tem 2026 |
36İzleyin | CVE-2024-36121İstismar yok | netty-incubator-codec-ohttp's BoringSSLAEADContext Repeats Noncesnetty · netty-incubator-codec-ohttp · CWE-190 | Kritik9,1 | — | %0,3 | 4 Haz 2024 |
34İzleyin | CVE-2026-33871İstismar yok | Netty HTTP/2 CONTINUATION Frame Flood DoS via Zero-Byte Frame Bypassnetty · netty · CWE-770 | Yüksek8,7 | — | %1,2 | 27 Mar 2026 |
34İzleyin | CVE-2026-48059İstismar yok | Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustionnetty · netty · CWE-401 | Yüksek8,7 | — | %0,9 | 12 Haz 2026 |
34İzleyin | CVE-2026-48006İstismar yok | Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregatornetty · netty · CWE-401 | Yüksek8,7 | — | %0,8 | 12 Haz 2026 |
34İzleyin | CVE-2026-75596İstismar yok | Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsingnetty · netty · CWE-407 | Yüksek8,7 | — | %0,7 | 19 Ağu 2026 |
34İzleyin | CVE-2026-56745İstismar yok | Netty SpdyHttpDecoder: ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustionnetty · netty · CWE-400 | Yüksek8,7 | — | %0,6 | 21 Tem 2026 |
34İzleyin | CVE-2026-55851İstismar yok | Netty codec-haproxy: Signed-Byte Sentinel Collision in HAProxyMessageDecoder Leads to Unbounded Memory Exhaustionnetty · netty · CWE-400 | Yüksek8,7 | — | %0,6 | 21 Tem 2026 |
34İzleyin | CVE-2026-59901İstismar yok | Netty Bzip2Decoder: Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hangnetty · netty · CWE-835 | Yüksek8,7 | — | %0,5 | 29 Tem 2026 |
33İzleyin | CVE-2016-4970İstismar yok | handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of netty · netty · CWE-835 | Yüksek7,5 | — | %11,3 | 13 Nis 2017 |
33İzleyin | CVE-2020-11612İstismar yok | The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream.netty · netty · CWE-770 | Yüksek7,5 | — | %9,2 | 7 Nis 2020 |
33İzleyin | CVE-2019-16869İstismar yok | Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leadsnetty · netty · CWE-444 | Yüksek7,5 | — | %8,4 | 26 Eyl 2019 |
33İzleyin | CVE-2026-56817İstismar yok | Netty: XML External Entity (XXE) injection via unconfigured XML factory when DTD and entity processing are enablednetty · netty · CWE-611 | Yüksek8,3 | — | %0,7 | 21 Tem 2026 |
32İzleyin | CVE-2021-37137İstismar yok | The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage.netty · netty · CWE-400 | Yüksek7,5 | — | %6,6 | 19 Eki 2021 |
32İzleyin | CVE-2021-37136İstismar yok | The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocatinetty · netty · CWE-400 | Yüksek7,5 | — | %5,9 | 19 Eki 2021 |
32İzleyin | CVE-2015-2156İstismar yok | Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before netty · netty · CWE-20 | Yüksek7,5 | — | %5,2 | 18 Eki 2017 |
- CVE-2023-4448790Hemen
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware10 Eki 2023
- CVE-2019-2044540Planlayın
HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Tr
KritikCVSS 9,1İstismar yokEPSS %13netty · netty29 Oca 2020
- CVE-2026-4567440Planlayın
Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records
KritikCVSS 10,0Kavram kanıtıEPSS %0netty · netty12 Haz 2026
- CVE-2026-4769140Planlayın
Netty has Insufficient Bailiwick Validation for NS Records
KritikCVSS 10,0İstismar yokEPSS %0netty · netty12 Haz 2026
- CVE-2019-2044439İzleyin
HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with
KritikCVSS 9,1İstismar yokEPSS %9netty · netty29 Oca 2020
- CVE-2026-4258139İzleyin
Netty: HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization
KritikCVSS 9,8İstismar yokEPSS %1netty · netty13 May 2026
- CVE-2026-4257936İzleyin
Netty: DNS Codec Input Validation Bypass in Netty (Encoder + Decoder)
KritikCVSS 9,1İstismar yokEPSS %1netty · netty13 May 2026
- CVE-2026-4258436İzleyin
Netty: HttpClientCodec response desynchronization
KritikCVSS 9,1İstismar yokEPSS %1netty · netty13 May 2026
- CVE-2026-7559536İzleyin
Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext
KritikCVSS 9,1İstismar yokEPSS %0netty · netty19 Ağu 2026
- CVE-2026-5682036İzleyin
Netty: Missing CertificateID Validation in OCSP Response Allows Replay Attacks
KritikCVSS 9,1İstismar yokEPSS %0netty · netty21 Tem 2026
- CVE-2024-3612136İzleyin
netty-incubator-codec-ohttp's BoringSSLAEADContext Repeats Nonces
KritikCVSS 9,1İstismar yokEPSS %0netty · netty-incubator-codec-ohttp4 Haz 2024
- CVE-2026-3387134İzleyin
Netty HTTP/2 CONTINUATION Frame Flood DoS via Zero-Byte Frame Bypass
YüksekCVSS 8,7İstismar yokEPSS %1netty · netty27 Mar 2026
- CVE-2026-4805934İzleyin
Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion
YüksekCVSS 8,7İstismar yokEPSS %1netty · netty12 Haz 2026
- CVE-2026-4800634İzleyin
Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator
YüksekCVSS 8,7İstismar yokEPSS %1netty · netty12 Haz 2026
- CVE-2026-7559634İzleyin
Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing
YüksekCVSS 8,7İstismar yokEPSS %1netty · netty19 Ağu 2026
- CVE-2026-5674534İzleyin
Netty SpdyHttpDecoder: ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustion
YüksekCVSS 8,7İstismar yokEPSS %1netty · netty21 Tem 2026
- CVE-2026-5585134İzleyin
Netty codec-haproxy: Signed-Byte Sentinel Collision in HAProxyMessageDecoder Leads to Unbounded Memory Exhaustion
YüksekCVSS 8,7İstismar yokEPSS %1netty · netty21 Tem 2026
- CVE-2026-5990134İzleyin
Netty Bzip2Decoder: Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang
YüksekCVSS 8,7İstismar yokEPSS %0netty · netty29 Tem 2026
- CVE-2016-497033İzleyin
handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of
YüksekCVSS 7,5İstismar yokEPSS %11netty · netty13 Nis 2017
- CVE-2020-1161233İzleyin
The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream.
YüksekCVSS 7,5İstismar yokEPSS %9netty · netty7 Nis 2020
- CVE-2019-1686933İzleyin
Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads
YüksekCVSS 7,5İstismar yokEPSS %8netty · netty26 Eyl 2019
- CVE-2026-5681733İzleyin
Netty: XML External Entity (XXE) injection via unconfigured XML factory when DTD and entity processing are enabled
YüksekCVSS 8,3İstismar yokEPSS %1netty · netty21 Tem 2026
- CVE-2021-3713732İzleyin
The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage.
YüksekCVSS 7,5İstismar yokEPSS %7netty · netty19 Eki 2021
- CVE-2021-3713632İzleyin
The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocati
YüksekCVSS 7,5İstismar yokEPSS %6netty · netty19 Eki 2021
- CVE-2015-215632İzleyin
Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before
YüksekCVSS 7,5İstismar yokEPSS %5netty · netty18 Eki 2017