REDHAT-BUG-2505422: High severity Netty Netty vulnerability
Netty is a network application framework for development of protocol servers and clients. Versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, are vulnerable to security control bypass during the origin evaluation process. CorsHandler provides a shortCircuit() configuration designed to reject unauthorized cross-origin requests immediately, acting as a security control before requests reach the application. However, due to a logical operator error in the origin evaluation process, this protection can be entirely bypassed. An attacker can bypass the short-circuit mechanism by sending a request with an Origin: null header. This failure forwards unauthorized requests to the backend application, bypassing intended access controls. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Nettyto a version that resolves this vulnerability.Fixed in 4.1.136.Final - Upgrade
Upgrade
Nettyto a version that resolves this vulnerability.Fixed in 4.2.16.Final
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2505422?
The severity of REDHAT-BUG-2505422 is high, rated at 7.
How do I fix REDHAT-BUG-2505422?
To fix REDHAT-BUG-2505422, upgrade Netty to versions beyond 4.2.15.Final or 4.1.135.Final.
What does the vulnerability REDHAT-BUG-2505422 affect?
REDHAT-BUG-2505422 affects the Netty network application framework specifically in versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final.
What type of vulnerability is REDHAT-BUG-2505422?
REDHAT-BUG-2505422 is a security control bypass vulnerability related to the origin evaluation process in CorsHandler.
When was REDHAT-BUG-2505422 published?
REDHAT-BUG-2505422 was published on July 21, 2026.