CVE-2026-93576: Io.netty/netty-codec-smtp: netty netty-codec-smtp — smtp command-name field is not crlf-validated (incomplete fix of cve-2025-59419)
Published Sep 18, 2026
·Updated
Netty netty-codec-smtp — SMTP command-name field is not CRLF-validated (incomplete fix of CVE-2025-59419)
Affected Software
1 affected component
io.netty/netty-codec-smtp
Event History
Sep 18, 2026
CVE Published
via MITRE·02:33 PM
Data Sourced
via MITRE·02:33 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates that exploitation is network-accessible, requires no privileges, no user interaction, and has low attack complexity.
2
What is the primary security impact?
The reported impact is integrity compromise; confidentiality and availability impacts are not indicated in the provided CVSS vector.