Where
-Infinity
0

maven/io.netty:netty-handler-ssl-ocspNetty: Missing CertificateID Validation in OCSP Response Allows Replay Attacks

Risk 56
Severity
7.4
First published (updated )

Netty NettyNetty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)

Risk 43
Severity
7.5
First published (updated )

maven/io.netty:netty-codec-xmlNetty: XML External Entity (XXE) injection via unconfigured XML factory when DTD and entity processing are enabled

Risk 52
Severity
8.3
First published (updated )

Netty NettyNetty: Memory Exhaustion via HTTP/3 Reserved Frame Types

Risk 43
Severity
7.5
First published (updated )

maven/io.netty:netty-codec-httpNetty has a Security Control Bypass via CORS Short-Circuit Failure

Risk 37
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

maven/io.netty:netty-codec-httpNetty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation

Risk 43
Severity
7.5
First published (updated )

Netty NettyNetty SPDY SETTINGS frame count materializes unbounded settings map

Risk 43
Severity
7.5
First published (updated )

maven/io.netty:netty-codec-stompNetty: Denial of Service via Unbounded Headers in StompSubframeDecoder

Risk 43
Severity
7.5
First published (updated )

Netty NettyNetty is a network application framework for development of protocol servers and clients. Prior to v…

Risk 33
Severity
7
First published (updated )

Netty NettyNetty is a network application framework for development of protocol servers and clients. Prior to v…

Risk 33
Severity
7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Netty NettyNetty is a network application framework for development of protocol servers and clients. Prior to v…

Risk 33
Severity
7
First published (updated )

Netty NettyNetty is a network application framework for development of protocol servers and clients. Prior to v…

Risk 33
Severity
7
First published (updated )

Netty NettyNetty is a network application framework for development of protocol servers and clients. Prior to v…

Risk 33
Severity
7
First published (updated )

Netty NettyNetty is a network application framework for development of protocol servers and clients. Prior to v…

Risk 33
Severity
7
First published (updated )

Netty NettyNetty is a network application framework for development of protocol servers and clients. Prior to v…

Risk 33
Severity
7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Netty NettyNetty is a network application framework for development of protocol servers and clients. NoQuicToke…

Risk 33
Severity
7
First published (updated )

Netty NettyNetty susceptible to HTTP/2 Reset Attack with different on-the-wire signature

Risk 33
Severity
6.9
First published (updated )

Netty NettyNetty's HttpObjectDecoder skips arbitrary initial control characters when only initial CRLF characters are permitted

Risk 27
Severity
5.3
First published (updated )

Netty NettyNetty has unbounded pre-allocation in RedisArrayAggregator from RESP array length

Risk 43
Severity
7.5
First published (updated )

Netty NettyNetty's wrapping plain trust manager silently disables hostname verification

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Netty Netty QUICNetty QUIC stateless reset token material exposed through header-visible connection IDs

Risk 32
Severity
4.8
First published (updated )

Netty Netty HTTP/3 codecNetty HTTP/3 QPACK Blocked Streams Memory Exhaustion

Risk 43
Severity
7.5
First published (updated )

maven/io.netty:netty-codec-haproxyNetty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion

Risk 47
Severity
8.7
First published (updated )

maven/io.netty:netty-codec-http2netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion

Risk 43
Severity
7.5
First published (updated )

maven/io.netty:netty-codec-redisNetty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator

Risk 47
Severity
8.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

maven/io.netty:netty-resolver-dnsNetty has Insufficient Bailiwick Validation for NS Records

Risk 73
Severity
10
First published (updated )

maven/io.netty:netty-codec-http2Netty HTTP/2: Advertised MAX_CONCURRENT_STREAMS are not enforced

Risk 27
Severity
5.3
First published (updated )

maven/io.netty:netty-transport-sctpNetty: SCTP reassembly nests buffers without bound

Risk 43
Severity
7.5
First published (updated )

maven/io.netty:netty-resolver-dnsNetty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records

Risk 73
Severity
10
First published (updated )

maven/io.netty:netty-resolver-dnsNetty: DNS Cache Poisoning due to Predictable PRNG and Default Static Source Port

Risk 40
Severity
6.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203