CVE-2026-75329: Netty configuration distribution service vulnerability

Published Aug 26, 2026
·
Updated

The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanism. Attackers can directly obtain the full configuration of any project (including database passwords, API keys, etc.) by sending a TCP request without any credential.

Affected Software

1 affected component
Netty configuration distribution service<=1.3.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade super-diamond-server to a version that resolves this vulnerability.

    Fixed in 1.3.3
  2. Compensating control

    Disable or block network access to the Netty configuration distribution service listening on TCP port 8283 for super-diamond-server versions <= 1.3.3 until authentication is available.

Event History

Aug 26, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:16 PM
Description

Frequently Asked Questions

1

What access does an attacker need to retrieve configuration data?

An attacker only needs network access to the Netty configuration distribution service on port 8283. The service has no authentication mechanism, so no credentials are required.

2

What information could be exposed through this service?

An attacker can obtain the full configuration for any project. Exposed configuration may include database passwords, API keys, and other secrets stored in project configuration.

3

Which deployments are affected?

super-diamond-server versions 1.3.3 and earlier are affected where the Netty configuration distribution service is reachable on port 8283.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203