{"schema_version":1,"title":"Netty vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 20 vulnerabilities in Netty: 0 in the last 7 days and 16 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-93562, was published on 18 September 2026.","url":"https://junglewise.ai/threats/technologies/netty","json_url":"https://junglewise.ai/threats/technologies/netty.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/netty","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":11,"all_time":20,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":13,"last_90_days":16,"last_365_days":19},"latest":[{"cve":"CVE-2026-93562","cvss":6.5,"epss":0.0058,"slug":"cve-2026-93562-a-flaw-was-found-in-netty-s-http-1-decoder-incomplete-validation","title":"Netty HTTP/1 decoder request smuggling","severity":"medium","exploited":false,"published_at":"2026-09-18T21:18:46.977+00:00","url":"https://junglewise.ai/threats/cve-2026-93562-a-flaw-was-found-in-netty-s-http-1-decoder-incomplete-validation"},{"cve":"CVE-2026-93569","cvss":8.2,"epss":0.007,"slug":"cve-2026-93569-netty-http-1-to-http-2-conversion-authority-mismatch","title":"Netty HTTP/1 to HTTP/2 conversion authority mismatch","severity":"high","exploited":false,"published_at":"2026-09-18T15:17:20.743+00:00","url":"https://junglewise.ai/threats/cve-2026-93569-netty-http-1-to-http-2-conversion-authority-mismatch"},{"cve":"CVE-2026-93566","cvss":6.5,"epss":0.0064,"slug":"cve-2026-93566-netty-http-request-smuggling-via-control-characters-in-chunk-size","title":"Netty HTTP request smuggling via control characters in chunk size","severity":"medium","exploited":false,"published_at":"2026-09-18T15:17:20.29+00:00","url":"https://junglewise.ai/threats/cve-2026-93566-netty-http-request-smuggling-via-control-characters-in-chunk-size"},{"cve":"CVE-2026-93565","cvss":7.5,"epss":0.0064,"slug":"cve-2026-93565-netty-rtspdecoder-method-token-smuggling-in-rtsp-parsing","title":"Netty RtspDecoder method-token smuggling in RTSP parsing","severity":"high","exploited":false,"published_at":"2026-09-18T15:17:20.093+00:00","url":"https://junglewise.ai/threats/cve-2026-93565-netty-rtspdecoder-method-token-smuggling-in-rtsp-parsing"},{"cve":"CVE-2026-93564","cvss":7.5,"epss":0.0079,"slug":"cve-2026-93564-netty-reference-count-leak-in-haproxy-proxy-v2-decoder","title":"Netty reference-count leak in HAProxy PROXY-v2 decoder","severity":"high","exploited":false,"published_at":"2026-09-18T15:17:19.943+00:00","url":"https://junglewise.ai/threats/cve-2026-93564-netty-reference-count-leak-in-haproxy-proxy-v2-decoder"},{"cve":"CVE-2026-93558","cvss":7.5,"epss":0.0079,"slug":"cve-2026-93558-netty-websocketserverextensionhandler-denial-of-service","title":"Netty WebSocketServerExtensionHandler denial of service","severity":"high","exploited":false,"published_at":"2026-09-18T15:17:19.59+00:00","url":"https://junglewise.ai/threats/cve-2026-93558-netty-websocketserverextensionhandler-denial-of-service"},{"cve":"CVE-2026-93560","cvss":7.5,"epss":0.0058,"slug":"cve-2026-93560-netty-stomp-codec-integer-truncation-denial-of-service","title":"Netty STOMP codec integer truncation denial of service","severity":"high","exploited":false,"published_at":"2026-09-18T14:19:08.21+00:00","url":"https://junglewise.ai/threats/cve-2026-93560-netty-stomp-codec-integer-truncation-denial-of-service"},{"cve":"CVE-2026-93492","cvss":5.3,"epss":0.0064,"slug":"cve-2026-93492-netty-http-2-hpackencoder-denial-of-service","title":"Netty HTTP/2 HpackEncoder Denial of Service","severity":"medium","exploited":false,"published_at":"2026-09-18T13:18:38.877+00:00","url":"https://junglewise.ai/threats/cve-2026-93492-netty-http-2-hpackencoder-denial-of-service"},{"cve":"CVE-2026-93491","cvss":7.5,"epss":0.0087,"slug":"cve-2026-93491-netty-httpservercodec-denial-of-service-via-http-request","title":"Netty HttpServerCodec denial of service via HTTP request pipelining","severity":"high","exploited":false,"published_at":"2026-09-18T13:18:38.723+00:00","url":"https://junglewise.ai/threats/cve-2026-93491-netty-httpservercodec-denial-of-service-via-http-request"},{"cve":"CVE-2026-93488","cvss":7.5,"epss":0.007,"slug":"cve-2026-93488-netty-spdysessionhandler-unbounded-stream-denial-of-service","title":"Netty SpdySessionHandler unbounded stream denial of service","severity":"high","exploited":false,"published_at":"2026-09-18T12:17:30.667+00:00","url":"https://junglewise.ai/threats/cve-2026-93488-netty-spdysessionhandler-unbounded-stream-denial-of-service"},{"cve":"CVE-2026-93578","cvss":5.9,"epss":0.0029,"slug":"cve-2026-93578-netty-ocsp-client-eku-verification-bypass","title":"Netty OCSP Client EKU verification bypass","severity":"medium","exploited":false,"published_at":"2026-09-18T11:17:22.17+00:00","url":"https://junglewise.ai/threats/cve-2026-93578-netty-ocsp-client-eku-verification-bypass"},{"cve":"CVE-2026-93575","cvss":7.5,"epss":0.0066,"slug":"cve-2026-93575-a-flaw-was-found-in-netty-s-mqttdecoder-an-unauthenticated-remote","title":"Netty MqttDecoder MQTT packet validation bypass","severity":"high","exploited":false,"published_at":"2026-09-18T11:17:22.033+00:00","url":"https://junglewise.ai/threats/cve-2026-93575-a-flaw-was-found-in-netty-s-mqttdecoder-an-unauthenticated-remote"},{"cve":"CVE-2026-89044","cvss":6.5,"epss":0.0043,"slug":"cve-2026-89044-netty-http-transfer-encoding-request-smuggling","title":"Netty HTTP Transfer-Encoding request smuggling","severity":"medium","exploited":false,"published_at":"2026-09-10T18:18:16.243+00:00","url":"https://junglewise.ai/threats/cve-2026-89044-netty-http-transfer-encoding-request-smuggling"},{"cve":"CVE-2026-76816","cvss":3.5,"epss":0.0027,"slug":"cve-2026-76816-netty-mqttencoder-null-byte-injection-in-mqtt-fields","title":"Netty MqttEncoder null byte injection in MQTT fields","severity":"low","exploited":false,"published_at":"2026-08-24T20:17:19.477+00:00","url":"https://junglewise.ai/threats/cve-2026-76816-netty-mqttencoder-null-byte-injection-in-mqtt-fields"},{"cve":"CVE-2026-59903","cvss":6.5,"epss":0.0025,"slug":"cve-2026-59903-netty-corshandler-cache-poisoning-via-vary-header-overwrite","title":"Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.http.c","severity":"medium","exploited":false,"published_at":"2026-08-17T18:17:36.25+00:00","url":"https://junglewise.ai/threats/cve-2026-59903-netty-corshandler-cache-poisoning-via-vary-header-overwrite"},{"cve":"CVE-2026-56818","cvss":6.5,"epss":0.0047,"slug":"cve-2026-56818-netty-redisarrayaggregator-memory-leak-in-resp-decoding","title":"Netty RedisArrayAggregator memory leak in RESP decoding","severity":"medium","exploited":false,"published_at":"2026-08-07T17:16:13+00:00","url":"https://junglewise.ai/threats/cve-2026-56818-netty-redisarrayaggregator-memory-leak-in-resp-decoding"},{"cve":"CVE-2026-42582","cvss":7.5,"epss":0.0049,"slug":"cve-2026-42582-netty-unbounded-memory-allocation-in-http-3-qpack-decoder","title":"Netty unbounded memory allocation in HTTP/3 QPACK decoder","severity":"high","exploited":false,"published_at":"2026-05-13T19:17:23.763+00:00","url":"https://junglewise.ai/threats/cve-2026-42582-netty-unbounded-memory-allocation-in-http-3-qpack-decoder"},{"cve":"CVE-2026-42577","cvss":7.5,"epss":0.0058,"slug":"cve-2026-42577-netty-denial-of-service-in-epoll-transport-via-rst-on-half-closed","title":"Netty denial of service in epoll transport via RST on half-closed connection","severity":"high","exploited":false,"published_at":"2026-05-13T19:17:23.063+00:00","url":"https://junglewise.ai/threats/cve-2026-42577-netty-denial-of-service-in-epoll-transport-via-rst-on-half-closed"},{"cve":"CVE-2026-41417","cvss":5.3,"epss":0.0034,"slug":"cve-2026-41417-netty-crlf-injection-in-defaulthttprequest-seturi","title":"Netty CRLF injection in DefaultHttpRequest setUri","severity":"medium","exploited":false,"published_at":"2026-05-06T22:16:25.78+00:00","url":"https://junglewise.ai/threats/cve-2026-41417-netty-crlf-injection-in-defaulthttprequest-seturi"},{"cve":"CVE-2019-16869","cvss":7.5,"epss":0.0842,"slug":"cve-2019-16869-netty-http-request-smuggling-via-header-whitespace-mishandling","title":"Netty HTTP request smuggling via header whitespace mishandling","severity":"high","exploited":false,"published_at":"2019-10-11T18:41:23+00:00","url":"https://junglewise.ai/threats/cve-2019-16869-netty-http-request-smuggling-via-header-whitespace-mishandling"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":12},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Netty Codec HTTP/3","slug":"codec-http-3","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/codec-http-3"},{"name":"Netty-Resolver-Dns","slug":"netty-resolver-dns","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/netty-resolver-dns"}],"technology":{"hub":true,"name":"Netty","slug":"netty","vendor":{"name":"Netty","slug":"netty","url":"https://junglewise.ai/threats/vendors/netty"},"aliases":["netty-codec-redis"],"category":"library","homepage":"https://netty.io","description":"An event-driven network application framework for rapid development of maintainable, high-performance protocol servers and clients.","url":"https://junglewise.ai/threats/technologies/netty"},"most_severe":[{"cve":"CVE-2026-93569","cvss":8.2,"epss":0.007,"slug":"cve-2026-93569-netty-http-1-to-http-2-conversion-authority-mismatch","title":"Netty HTTP/1 to HTTP/2 conversion authority mismatch","severity":"high","exploited":false,"published_at":"2026-09-18T15:17:20.743+00:00","url":"https://junglewise.ai/threats/cve-2026-93569-netty-http-1-to-http-2-conversion-authority-mismatch"},{"cve":"CVE-2019-16869","cvss":7.5,"epss":0.0842,"slug":"cve-2019-16869-netty-http-request-smuggling-via-header-whitespace-mishandling","title":"Netty HTTP request smuggling via header whitespace mishandling","severity":"high","exploited":false,"published_at":"2019-10-11T18:41:23+00:00","url":"https://junglewise.ai/threats/cve-2019-16869-netty-http-request-smuggling-via-header-whitespace-mishandling"},{"cve":"CVE-2026-93491","cvss":7.5,"epss":0.0087,"slug":"cve-2026-93491-netty-httpservercodec-denial-of-service-via-http-request","title":"Netty HttpServerCodec denial of service via HTTP request pipelining","severity":"high","exploited":false,"published_at":"2026-09-18T13:18:38.723+00:00","url":"https://junglewise.ai/threats/cve-2026-93491-netty-httpservercodec-denial-of-service-via-http-request"},{"cve":"CVE-2026-93564","cvss":7.5,"epss":0.0079,"slug":"cve-2026-93564-netty-reference-count-leak-in-haproxy-proxy-v2-decoder","title":"Netty reference-count leak in HAProxy PROXY-v2 decoder","severity":"high","exploited":false,"published_at":"2026-09-18T15:17:19.943+00:00","url":"https://junglewise.ai/threats/cve-2026-93564-netty-reference-count-leak-in-haproxy-proxy-v2-decoder"},{"cve":"CVE-2026-93558","cvss":7.5,"epss":0.0079,"slug":"cve-2026-93558-netty-websocketserverextensionhandler-denial-of-service","title":"Netty WebSocketServerExtensionHandler denial of service","severity":"high","exploited":false,"published_at":"2026-09-18T15:17:19.59+00:00","url":"https://junglewise.ai/threats/cve-2026-93558-netty-websocketserverextensionhandler-denial-of-service"},{"cve":"CVE-2026-93488","cvss":7.5,"epss":0.007,"slug":"cve-2026-93488-netty-spdysessionhandler-unbounded-stream-denial-of-service","title":"Netty SpdySessionHandler unbounded stream denial of service","severity":"high","exploited":false,"published_at":"2026-09-18T12:17:30.667+00:00","url":"https://junglewise.ai/threats/cve-2026-93488-netty-spdysessionhandler-unbounded-stream-denial-of-service"},{"cve":"CVE-2026-93575","cvss":7.5,"epss":0.0066,"slug":"cve-2026-93575-a-flaw-was-found-in-netty-s-mqttdecoder-an-unauthenticated-remote","title":"Netty MqttDecoder MQTT packet validation bypass","severity":"high","exploited":false,"published_at":"2026-09-18T11:17:22.033+00:00","url":"https://junglewise.ai/threats/cve-2026-93575-a-flaw-was-found-in-netty-s-mqttdecoder-an-unauthenticated-remote"},{"cve":"CVE-2026-93565","cvss":7.5,"epss":0.0064,"slug":"cve-2026-93565-netty-rtspdecoder-method-token-smuggling-in-rtsp-parsing","title":"Netty RtspDecoder method-token smuggling in RTSP parsing","severity":"high","exploited":false,"published_at":"2026-09-18T15:17:20.093+00:00","url":"https://junglewise.ai/threats/cve-2026-93565-netty-rtspdecoder-method-token-smuggling-in-rtsp-parsing"},{"cve":"CVE-2026-93560","cvss":7.5,"epss":0.0058,"slug":"cve-2026-93560-netty-stomp-codec-integer-truncation-denial-of-service","title":"Netty STOMP codec integer truncation denial of service","severity":"high","exploited":false,"published_at":"2026-09-18T14:19:08.21+00:00","url":"https://junglewise.ai/threats/cve-2026-93560-netty-stomp-codec-integer-truncation-denial-of-service"},{"cve":"CVE-2026-42577","cvss":7.5,"epss":0.0058,"slug":"cve-2026-42577-netty-denial-of-service-in-epoll-transport-via-rst-on-half-closed","title":"Netty denial of service in epoll transport via RST on half-closed connection","severity":"high","exploited":false,"published_at":"2026-05-13T19:17:23.063+00:00","url":"https://junglewise.ai/threats/cve-2026-42577-netty-denial-of-service-in-epoll-transport-via-rst-on-half-closed"}],"generated_at":"2026-09-26T15:07:00.181821+00:00"}