Vulnerabilidades em netty

91 resultados
Análise Vexday

O framework Netty acumula 60 CVEs catalogadas, com destaque para um volume expressivo de 38 entradas registradas nos últimos 90 dias, o que indica um período recente de descoberta ou catalogação acelerada de vulnerabilidades e merece acompanhamento próximo por equipes de segurança. A taxa de exploração ativa está abaixo da média geral do catálogo KEV, sem nenhuma CVE confirmada em uso por atores maliciosos no momento, e sem registros de severidade crítica ou provas de conceito públicas disponíveis. O tipo de falha mais recorrente é CWE-400 (consumo descontrolado de recursos), padrão associado a condições de negação de serviço que, embora frequentemente subestimado, pode impactar disponibilidade em ambientes de alta carga. A CVE mais relevante no cenário atual é CVE-2021-21295, com score EPSS de 0,1889, sugerindo probabilidade moderada de exploração e justificando priorização na aplicação de correções para instalações que ainda não foram atualizadas.

CVE-2026-45674HIGHNetty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME RecordsEPSS 0.3%CVE-2026-50560MEDIUMNetty susceptible to HTTP/2 Reset Attack with different on-the-wire signatureEPSS 0.3%CVE-2026-54251HIGHnetty-incubator-codec-ohttp: [OHttpServerCodec] Native Direct-Memory Leak on AEAD Decryption Failure Leads to Gateway Denial of ServiceEPSS 0.3%CVE-2026-47244MEDIUMNetty HTTP/2: Advertised MAX_CONCURRENT_STREAMS are not enforcedEPSS 0.3%CVE-2026-56818MEDIUMNetty: RedisArrayAggregator max-elements failure leaves retained partial aggregate stateEPSS 0.3%CVE-2026-44892HIGHNetty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header SizeEPSS 0.3%CVE-2024-36121MEDIUM netty-incubator-codec-ohttp's BoringSSLAEADContext Repeats NoncesEPSS 0.3%CVE-2026-42585MEDIUMNetty: HTTP Request Smuggling due to malformed Transfer-EncodingEPSS 0.3%CVE-2026-59901HIGHNetty Bzip2Decoder: Infinite Loop in RLE State Machine Leads to Event-Loop Thread HangEPSS 0.3%CVE-2026-45673MEDIUMNetty: DNS Cache Poisoning due to Predictable PRNG and Default Static Source PortEPSS 0.3%CVE-2026-62380MEDIUMNetty before 4.2.16.Final SOCKS Proxy Null Byte InjectionEPSS 0.3%CVE-2026-59898MEDIUMNetty: WebSockets V07/V08 handshaker missing Connection/Upgrade validationEPSS 0.2%CVE-2026-59921MEDIUMNetty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoderEPSS 0.2%CVE-2026-59903MEDIUMNetty: Cache Poisoning and Information Disclosure via CORS Vary Header OverwriteEPSS 0.2%CVE-2026-89044MEDIUMNetty 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final HTTP Request Smuggling via Transfer-EncodingEPSS 0.2%CVE-2026-59920MEDIUMNetty: STOMP CONNECT Frame Header InjectionEPSS 0.2%CVE-2026-50020MEDIUMNetty's HttpObjectDecoder skips arbitrary initial control characters when only initial CRLF characters are permittedEPSS 0.2%CVE-2026-59900MEDIUMNetty codec-http2: Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing BypassEPSS 0.2%CVE-2026-56820HIGHNetty: Missing CertificateID Validation in OCSP Response Allows Replay AttacksEPSS 0.2%CVE-2026-50009MEDIUMNetty QUIC stateless reset token material exposed through header-visible connection IDsEPSS 0.2%