Netty vulnerabilities
3 CVEs tracked
Netty appears in our reports as a widely-used asynchronous network application framework. Three critical vulnerabilities were highlighted in recent reports: premature forwarding of SslHandshakeCompletionEvent before OCSP validation (CVE-2026-56822), failure to deduplicate or validate Host headers in the HTTP/2-to-HTTP/1.x translation layer (CVE-2026-59900), and improper state clearing in the RedisArrayAggregator codec when the maxElement limit is exceeded (CVE-2026-56818). Defenders must immediately update all instances to versions 4.1.136.Final or 4.2.16.Final, and should implement additional network-level filtering, especially against HTTP/2 Host header manipulation risks.
Azərbaycanca: Netty, hesabatlarımızda geniş istifadə olunan asinxron şəbəkə framework'u kimi görünür. Son hesabatlarda üç kritik zəiflik aşkarlanıb: OCSP yoxlamasının vaxtından əvvəl tamamlanması (CVE-2026-56822), HTTP/2-dən HTTP/1.x-ə çevirmə qatında `Host` başlıqlarının düzgün yoxlanılmaması (CVE-2026-59900) və `RedisArrayAggregator` kodekində `maxElement` limiti aşıldıqda vəziyyətin səhv təmizlənməsi (CVE-2026-56818). Müdafiəçilər 4.1.136.Final və 4.2.16.Final versiyalarından əvvəlki versiyaları istifadə edən bütün tətbiqləri dərhal yeniləməli, xüsusilə HTTP/2 `Host` başlıq manipulyasiyası riskinə qarşı şəbəkə səviyyəsində əlavə filtrasiya tətbiq etməlidir.
This vendor's CVEs3
This hub is built from skopnix's own reporting on Netty: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.