Netty
netty
69 CVEs • 2 products
Products (2)
Click to collapseToggle
Products (2)
Click to collapse
CVEs (69)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Debian FedoraprojectNetapp+2 more13Communications Brm Elastic Charging Engine Communications Cloud Native Core Service Communication ProxyCommunications Design Studio+10 moreJun 17, 2026 Apr 7, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send a large ZlibEncoded byte stream to the Netty server, forcing the server...Show more |
6Apache CanonicalDebian+3 more7Debian Linux FedoraJboss Amq Clients+4 moreJun 17, 2026 Jan 29, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header. |
5Canonical DebianFedoraproject+2 more6Debian Linux FedoraJboss Amq Clients+3 moreJun 17, 2026 Jan 29, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an "invalid fold." |
4Debian FedoraprojectNetty+1 more6Debian Linux FedoraJboss Enterprise Application Platform+3 moreJun 17, 2026 Jan 27, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line) and a later Content-Length header. This issue exists because of an inc...Show more |
4Canonical DebianNetty+1 more4Debian Linux Jboss Enterprise Application PlatformNetty+1 moreJun 17, 2026 Sep 26, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling. |
3Lightbend NettyPlayframework3Netty Play FrameworkPlay FrameworkMay 13, 2026 Oct 18, 2017 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before 2.3.9 might allow remote attackers to bypass the httpOnly flag on cookies and ob...Show more |
3Apache NettyRedhat4Cassandra Jboss Data GridJboss Middleware Text Only Advisories+1 moreMay 13, 2026 Apr 13, 2017 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (infinite loop). |
The SslHandler in Netty before 3.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted SSLv2Hello message. |
WebSocket08FrameDecoder in Netty 3.6.x before 3.6.9, 3.7.x before 3.7.1, 3.8.x before 3.8.2, 3.9.x before 3.9.1, and 4.0.x before 4.0.19 allows remote attackers to cause a denial of service (memory consumption) via a Tex...Show more |