Vulnerabilidades en netty

79 resultados
Análisis Vexday

O framework Netty acumula 60 CVEs catalogadas, com destaque para um volume expressivo de 38 entradas registradas nos últimos 90 dias, o que indica um período recente de descoberta ou catalogação acelerada de vulnerabilidades e merece acompanhamento próximo por equipes de segurança. A taxa de exploração ativa está abaixo da média geral do catálogo KEV, sem nenhuma CVE confirmada em uso por atores maliciosos no momento, e sem registros de severidade crítica ou provas de conceito públicas disponíveis. O tipo de falha mais recorrente é CWE-400 (consumo descontrolado de recursos), padrão associado a condições de negação de serviço que, embora frequentemente subestimado, pode impactar disponibilidade em ambientes de alta carga. A CVE mais relevante no cenário atual é CVE-2021-21295, com score EPSS de 0,1889, sugerindo probabilidade moderada de exploração e justificando priorização na aplicação de correções para instalações que ainda não foram atualizadas.

CVE-2021-21295MEDIUMPossible request smuggling in HTTP/2 due missing validationEPSS 18.9%CVE-2021-21409MEDIUMPossible request smuggling in HTTP/2 due missing validation of content-lengthEPSS 4.9%CVE-2021-43797MEDIUMHTTP fails to validate against control chars in header names which may lead to HTTP request smugglingEPSS 2.7%CVE-2023-34462MEDIUMnetty-handler SniHandler 16MB allocationEPSS 2.5%CVE-2025-24970HIGHSslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngineEPSS 2.1%CVE-2021-21290MEDIUMLocal Information Disclosure Vulnerability in Netty on Unix-Like systems due temporary filesEPSS 1.8%CVE-2025-59419MEDIUMNetty netty-codec-smtp SMTP Command Injection Vulnerability Allowing Email ForgeryEPSS 1.6%CVE-2022-41881MEDIUMNetty project is an event-driven asynchronous network application framework. In versions prior to 4.1.86.Final, a StackOverflowError can be EPSS 1.5%CVE-2024-29025MEDIUMNetty HttpPostRequestDecoder can OOMEPSS 1.4%CVE-2026-33871HIGHNetty HTTP/2 CONTINUATION Frame Flood DoS via Zero-Byte Frame BypassEPSS 1.1%CVE-2025-55163HIGHNetty MadeYouReset HTTP/2 DDoS VulnerabilityEPSS 1.0%CVE-2022-24823MEDIUMLocal Information Disclosure Vulnerability in io.netty:netty-codec-httpEPSS 1.0%CVE-2026-44249HIGHNetty has an IPv6 Subnet Filter Bypass via Incorrect Comparator MaskingEPSS 1.0%CVE-2026-42587HIGHNetty: HttpContentDecompressor maxAllocation bypass via Content-Encoding: br/zstd/snappy enables decompression bomb DoSEPSS 1.0%CVE-2026-42579HIGHNetty: DNS Codec Input Validation Bypass in Netty (Encoder + Decoder)EPSS 1.0%CVE-2026-42578LOWNetty: HTTP Header Injection via HttpProxyHandler Disabled ValidationEPSS 1.0%CVE-2022-41915MEDIUMNetty project is an event-driven asynchronous network application framework. Starting in version 4.1.83.Final and prior to 4.1.86.Final, wheEPSS 0.9%CVE-2026-45416HIGHNetty: SNI handler pre-allocates up to 16 MiB from nine attacker bytesEPSS 0.9%CVE-2026-42584HIGHNetty: HttpClientCodec response desynchronizationEPSS 0.8%CVE-2025-58056LOWNetty is vulnerable to request smuggling due to incorrect parsing of chunk extensionsEPSS 0.7%