-Infinity
0

Netty NettyNetty: Memory Leak in DNS Record Decoder via Malformed Domain Names

Risk 27
Severity
5.3
First published (updated )

Netty NettyNetty: Denial of Service in XmlFrameDecoder via CPU Exhaustion

Risk 43
Severity
7.5
First published (updated )

maven/io.netty:netty-codec-redisNetty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state

Risk 40
Severity
6.5
First published (updated )

Netty netty-codec-httpNetty is a network application framework for development of protocol servers and clients. Prior to 4…

Risk 33
Severity
7
First published (updated )

maven/io.netty:netty-codec-httpNetty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder

Risk 38
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

maven/io.netty:netty-codec-stompNetty: STOMP CONNECT Frame Header Injection

Risk 38
Severity
6.5
First published (updated )

maven/io.netty:netty-codec-haproxyNetty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address

Risk 32
Severity
5.5
First published (updated )

Netty NettyNetty Bzip2Decoder: Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang

Risk 47
Severity
8.7
First published (updated )

maven/io.netty:netty-codec-http2Netty codec-http2: Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass

Risk 43
Severity
6.9
First published (updated )

maven/io.netty:netty-codec-httpNetty HttpContentEncoder: Unbounded Per-Connection Queue Growth via HTTP/1.1 Pipelining Leads to Denial of Service

Risk 43
Severity
6.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

maven/io.netty:netty-codec-httpNetty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation

Risk 43
Severity
6.3
First published (updated )

maven/io.netty:netty-handler-ssl-ocspNetty: TOCTOU in OcspServerCertificateValidator

Risk 56
Severity
7.4
First published (updated )

maven/io.netty:netty-handler-ssl-ocspNetty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator

Risk 56
Severity
7.4
First published (updated )

Netty NettyNetty is a network application framework for development of protocol servers and clients. In version…

Risk 33
Severity
7
First published (updated )

Netty NettyNetty is a network application framework for development of protocol servers and clients. In version…

Risk 33
Severity
7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Netty NettyNetty is a network application framework for development of protocol servers and clients. In version…

Risk 33
Severity
7
First published (updated )

Netty NettyNetty is a network application framework for development of protocol servers and clients. In version…

Risk 33
Severity
7
First published (updated )

Netty NettyNetty is a network application framework for development of protocol servers and clients. In version…

Risk 33
Severity
7
First published (updated )

Netty NettyNetty is a network application framework for development of protocol servers and clients. Versions 4…

Risk 33
Severity
7
First published (updated )

Netty NettyNetty: Missing CertificateID Validation in OCSP Response Allows Replay Attacks

Risk 66
Severity
9.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Netty NettyNetty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)

Risk 43
Severity
7.5
First published (updated )

Netty NettyNetty: XML External Entity (XXE) injection via unconfigured XML factory when DTD and entity processing are enabled

Risk 86
Severity
8.3
First published (updated )

Netty NettyNetty: Memory Exhaustion via HTTP/3 Reserved Frame Types

Risk 43
Severity
7.5
First published (updated )

Netty NettyNetty has a Security Control Bypass via CORS Short-Circuit Failure

Risk 37
Severity
6.5
First published (updated )

maven/io.netty:netty-codec-httpNetty SpdyHttpDecoder: ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustion

Risk 47
Severity
8.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

maven/io.netty:netty-codec-haproxyNetty codec-haproxy: Signed-Byte Sentinel Collision in HAProxyMessageDecoder Leads to Unbounded Memory Exhaustion

Risk 47
Severity
8.7
First published (updated )

Netty NettyNetty is a network application framework for development of protocol servers and clients. Prior to 4…

Risk 33
Severity
7
First published (updated )

Netty NettyNetty is a network application framework for development of protocol servers and clients. Prior to 4…

Risk 33
Severity
7
First published (updated )

maven/io.netty:netty-codec-httpNetty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation

Risk 43
Severity
7.5
First published (updated )

Netty NettyNetty SPDY SETTINGS frame count materializes unbounded settings map

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203