| Netty versions 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final fail to properly validate the final transfer… CVE-2026-89044 | Severity medium |
| Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, the default… CVE-2026-75596 | Severity high |
| io.netty/netty-handler: Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext CVE-2026-75595 | Severity critical |
| io.netty/netty-codec-dns: Netty: Denial of Service via Memory Leak in DNS Record Decoder with Malformed Domain Names CVE-2026-73508 | Severity high |
| io.netty/netty-codec-xml: Netty: Denial of Service via CPU Exhaustion in XmlFrameDecoder CVE-2026-73507 | Severity high |
| io.netty/netty: Netty: Information disclosure via CORS Vary header overwrite CVE-2026-59903 | Severity high |
| io.netty/netty-transport-sctp: Netty: Denial of Service via SCTP memory exhaustion CVE-2026-59902 | Severity high |
| io.netty/netty-codec-redis: Netty: Memory leak in netty-codec-redis CVE-2026-56818 | Severity high |
| netty-codec-redis: Netty: Denial of Service via malicious Redis array header CVE-2026-50011 | Severity high |
| netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass CVE-2026-50010 | Severity high |
| netty-codec-haproxy: Netty HAProxy PROXY protocol v2 codec: Denial of Service via memory leak from crafted PROXY protocol headers CVE-2026-48059 | Severity high |
| netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak CVE-2026-48043 | Severity high |
| netty-codec-redis: Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator CVE-2026-48006 | Severity high |
| io.netty/netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records CVE-2026-47691 | Severity critical |
| netty-transport-sctp: Netty-transport-sctp: Denial of Service due to unbounded memory growth from SctpMessage fragments CVE-2026-46340 | Severity high |
| netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation CVE-2026-45674 | Severity critical |
| netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake CVE-2026-45416 | Severity high |
| netty-codec-haproxy: Netty-codec-haproxy: Denial of Service via malformed HAProxy message CVE-2026-44893 | Severity high |
| netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payloads CVE-2026-44890 | Severity high |
| netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payload with deeply nested arrays CVE-2026-44250 | Severity high |
| netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation CVE-2026-44249 | Severity high |
| netty: io.netty/netty-codec-mqtt: Netty: Denial of Service due to excessive resource consumption from crafted MQTT 5 header CVE-2026-44248 | Severity high |
| netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content… CVE-2026-42587 | Severity high |
| netty: io.netty/netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion CVE-2026-42584 | Severity critical |
| netty: io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers CVE-2026-42581 | Severity critical |
| netty: Netty: High integrity impact due to improper DNS domain name constraint enforcement CVE-2026-42579 | Severity critical |
| netty: io.netty/netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation CVE-2026-42578 | Severity high |
| netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood CVE-2026-33871 | Severity high |
| io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values CVE-2026-33870 | Severity high |