{"schema_version":1,"title":"Netty Project vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 62 vulnerabilities in Netty Project: 4 in the last 7 days and 30 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-100666, was published on 26 September 2026. 7 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/netty-project","json_url":"https://junglewise.ai/threats/vendors/netty-project.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/netty-project","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":37,"all_time":62,"critical":0,"exploited":0,"last_7_days":4,"last_30_days":11,"last_90_days":30,"last_365_days":62},"latest":[{"cve":"CVE-2026-100666","cvss":7.3,"slug":"cve-2026-100666-netty-s-httpservercodec-io-netty-netty-codec-http-in-versions-4","title":"Netty HttpServerCodec response desynchronization","severity":"high","exploited":false,"published_at":"2026-09-26T14:16:49.83+00:00","url":"https://junglewise.ai/threats/cve-2026-100666-netty-s-httpservercodec-io-netty-netty-codec-http-in-versions-4"},{"cve":"CVE-2026-100665","cvss":7.5,"slug":"cve-2026-100665-netty-versions-from-4-2-11-final-before-4-2-18-final-contain-an","title":"Netty incomplete hostname verification in QUIC certificate verification","severity":"high","exploited":false,"published_at":"2026-09-26T14:16:49.677+00:00","url":"https://junglewise.ai/threats/cve-2026-100665-netty-versions-from-4-2-11-final-before-4-2-18-final-contain-an"},{"cve":"CVE-2026-100664","cvss":7.5,"slug":"cve-2026-100664-netty-s-http-3-codec-io-netty-netty-codec-http3-versions-4-2-2","title":"Netty HTTP/3 codec Host header authority confusion","severity":"high","exploited":false,"published_at":"2026-09-26T14:16:49.54+00:00","url":"https://junglewise.ai/threats/cve-2026-100664-netty-s-http-3-codec-io-netty-netty-codec-http3-versions-4-2-2"},{"cve":"CVE-2026-100659","cvss":6.5,"slug":"cve-2026-100659-netty-s-http-3-codec-io-netty-netty-codec-http3-in-versions-4-2","title":"Netty HTTP/3 codec host header validation bypass","severity":"medium","exploited":false,"published_at":"2026-09-26T14:16:48.83+00:00","url":"https://junglewise.ai/threats/cve-2026-100659-netty-s-http-3-codec-io-netty-netty-codec-http3-in-versions-4-2"},{"cve":"CVE-2026-93574","cvss":6.5,"epss":0.0087,"slug":"cve-2026-93574-a-flaw-was-found-in-netty-s-netty-codec-http-component-a-remote","title":"Netty netty-codec-http request smuggling via chunk-size parsing","severity":"medium","exploited":false,"published_at":"2026-09-18T21:18:48.277+00:00","url":"https://junglewise.ai/threats/cve-2026-93574-a-flaw-was-found-in-netty-s-netty-codec-http-component-a-remote"},{"cve":"CVE-2026-93579","cvss":6.5,"epss":0.0058,"slug":"cve-2026-93579-a-flaw-was-found-in-netty-s-http-2-stack-this-vulnerability","title":"Netty HTTP/2 header injection vulnerability","severity":"medium","exploited":false,"published_at":"2026-09-18T17:17:06.89+00:00","url":"https://junglewise.ai/threats/cve-2026-93579-a-flaw-was-found-in-netty-s-http-2-stack-this-vulnerability"},{"cve":"CVE-2026-93576","cvss":7.5,"epss":0.0046,"slug":"cve-2026-93576-a-flaw-was-found-in-netty-netty-codec-smtp-the-component-does-not","title":"Netty netty-codec-smtp CR/LF injection in SMTP command parsing","severity":"high","exploited":false,"published_at":"2026-09-18T15:17:21.167+00:00","url":"https://junglewise.ai/threats/cve-2026-93576-a-flaw-was-found-in-netty-netty-codec-smtp-the-component-does-not"},{"cve":"CVE-2026-93572","cvss":7.5,"epss":0.0058,"slug":"cve-2026-93572-a-flaw-was-found-in-netty-s-redisarrayaggregator-component-a","title":"Netty RedisArrayAggregator heap memory exhaustion","severity":"high","exploited":false,"published_at":"2026-09-18T11:17:21.9+00:00","url":"https://junglewise.ai/threats/cve-2026-93572-a-flaw-was-found-in-netty-s-redisarrayaggregator-component-a"},{"cve":"CVE-2026-93563","cvss":7.5,"epss":0.0056,"slug":"cve-2026-93563-a-flaw-was-found-in-netty-s-smtpresponsedecoder-component-a","title":"Netty SmtpResponseDecoder unbounded memory accumulation","severity":"high","exploited":false,"published_at":"2026-09-18T11:17:21.773+00:00","url":"https://junglewise.ai/threats/cve-2026-93563-a-flaw-was-found-in-netty-s-smtpresponsedecoder-component-a"},{"cve":"CVE-2026-93494","cvss":7.5,"epss":0.0058,"slug":"cve-2026-93494-a-flaw-was-found-in-netty-s-stompsubframedecoder-component-a","title":"Netty memory leak in StompSubframeDecoder","severity":"high","exploited":false,"published_at":"2026-09-18T08:17:02.647+00:00","url":"https://junglewise.ai/threats/cve-2026-93494-a-flaw-was-found-in-netty-s-stompsubframedecoder-component-a"},{"cve":"CVE-2026-54251","cvss":4,"epss":0.0051,"slug":"cve-2026-54251-netty-netty-incubator-codec-ohttp-memory-leak-in-aead-decryption","title":"netty-incubator-codec-ohttp implements Oblivious HTTP (OHTTP) gateway and client functionality using Netty. Prior to 0.0.23.Final, the OHTTP","severity":"high","exploited":false,"published_at":"2026-09-15T18:17:22.78+00:00","url":"https://junglewise.ai/threats/cve-2026-54251-netty-netty-incubator-codec-ohttp-memory-leak-in-aead-decryption"},{"cve":"CVE-2026-63202","cvss":7.5,"slug":"cve-2026-63202-netty-incubator-ohttp-binaryhttpparser-infinite-loop-dos","title":"Netty Incubator OHTTP BinaryHttpParser infinite loop DoS","severity":"high","exploited":false,"published_at":"2026-08-20T18:43:38+00:00","url":"https://junglewise.ai/threats/cve-2026-63202-netty-incubator-ohttp-binaryhttpparser-infinite-loop-dos"},{"cve":"CVE-2026-59902","cvss":7.5,"epss":0.0067,"slug":"cve-2026-59902-netty-sctpmessagecompletionhandler-memory-exhaustion","title":"Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.sctp.S","severity":"high","exploited":false,"published_at":"2026-08-17T18:17:36.087+00:00","url":"https://junglewise.ai/threats/cve-2026-59902-netty-sctpmessagecompletionhandler-memory-exhaustion"},{"cve":"CVE-2026-59920","cvss":6.5,"epss":0.0042,"slug":"cve-2026-59920-netty-stomp-header-injection-in-connect-frames","title":"Netty STOMP header injection in CONNECT frames","severity":"medium","exploited":false,"published_at":"2026-07-29T18:16:56.757+00:00","url":"https://junglewise.ai/threats/cve-2026-59920-netty-stomp-header-injection-in-connect-frames"},{"cve":"CVE-2026-59919","cvss":5.5,"epss":0.0017,"slug":"cve-2026-59919-netty-crlf-injection-in-haproxymessageencoder-af-unix-addresses","title":"Netty CRLF injection in HAProxyMessageEncoder AF_UNIX addresses","severity":"medium","exploited":false,"published_at":"2026-07-29T18:16:56.61+00:00","url":"https://junglewise.ai/threats/cve-2026-59919-netty-crlf-injection-in-haproxymessageencoder-af-unix-addresses"},{"cve":"CVE-2026-59900","cvss":4,"epss":0.004,"slug":"cve-2026-59900-netty-request-smuggling-via-host-header-duplication-in-http-2","title":"Netty request smuggling via Host header duplication in HTTP/2 translation","severity":"medium","exploited":false,"published_at":"2026-07-29T18:16:56.32+00:00","url":"https://junglewise.ai/threats/cve-2026-59900-netty-request-smuggling-via-host-header-duplication-in-http-2"},{"cve":"CVE-2026-59899","cvss":4,"epss":0.0061,"slug":"cve-2026-59899-netty-resource-exhaustion-in-httpcontentencoder-via-http","title":"Netty resource exhaustion in HttpContentEncoder via HTTP pipelining","severity":"medium","exploited":false,"published_at":"2026-07-29T18:16:56.137+00:00","url":"https://junglewise.ai/threats/cve-2026-59899-netty-resource-exhaustion-in-httpcontentencoder-via-http"},{"cve":"CVE-2026-56822","cvss":7.4,"epss":0.0017,"slug":"cve-2026-56822-netty-toctou-race-condition-in-ocspservercertificatevalidator","title":"Netty TOCTOU race condition in OcspServerCertificateValidator","severity":"high","exploited":false,"published_at":"2026-07-29T00:16:38.717+00:00","url":"https://junglewise.ai/threats/cve-2026-56822-netty-toctou-race-condition-in-ocspservercertificatevalidator"},{"cve":"CVE-2026-56821","cvss":7.4,"epss":0.0022,"slug":"cve-2026-56821-netty-ocspservercertificatevalidator-certificate-revocation","title":"Netty OcspServerCertificateValidator certificate revocation bypass","severity":"high","exploited":false,"published_at":"2026-07-29T00:16:38.573+00:00","url":"https://junglewise.ai/threats/cve-2026-56821-netty-ocspservercertificatevalidator-certificate-revocation"},{"cve":"CVE-2026-59921","cvss":5.7,"epss":0.0047,"slug":"cve-2026-59921-netty-crlf-injection-in-httppostrequestencoder-multipart","title":"Netty CRLF injection in HttpPostRequestEncoder multipart filenames","severity":"medium","exploited":false,"published_at":"2026-07-28T23:17:09.923+00:00","url":"https://junglewise.ai/threats/cve-2026-59921-netty-crlf-injection-in-httppostrequestencoder-multipart"},{"cvss":7.5,"slug":"netty-xmlframedecoder-denial-of-service-via-cpu-exhaustion-61b8c360","title":"Netty XmlFrameDecoder denial of service via CPU exhaustion","severity":"high","exploited":false,"published_at":"2026-07-24T16:53:04+00:00","url":"https://junglewise.ai/threats/netty-xmlframedecoder-denial-of-service-via-cpu-exhaustion-61b8c360"},{"cvss":5.3,"slug":"netty-memory-leak-in-dns-record-decoder-via-malformed-domain-names-d6a30ed2","title":"Netty memory leak in DNS Record Decoder via malformed domain names","severity":"medium","exploited":false,"published_at":"2026-07-24T16:52:50+00:00","url":"https://junglewise.ai/threats/netty-memory-leak-in-dns-record-decoder-via-malformed-domain-names-d6a30ed2"},{"cve":"CVE-2026-56820","cvss":7.4,"epss":0.0031,"slug":"cve-2026-56820-netty-ocspclient-revocation-check-bypass-via-improper","title":"Netty OcspClient revocation check bypass via improper CertificateID validation","severity":"high","exploited":false,"published_at":"2026-07-21T23:17:52.403+00:00","url":"https://junglewise.ai/threats/cve-2026-56820-netty-ocspclient-revocation-check-bypass-via-improper"},{"cve":"CVE-2026-56819","cvss":7.5,"epss":0.0067,"slug":"cve-2026-56819-netty-memory-leak-in-http-2-content-decompression","title":"Netty memory leak in HTTP/2 content decompression","severity":"high","exploited":false,"published_at":"2026-07-21T23:17:52.263+00:00","url":"https://junglewise.ai/threats/cve-2026-56819-netty-memory-leak-in-http-2-content-decompression"},{"cve":"CVE-2026-56817","cvss":4,"epss":0.0069,"slug":"cve-2026-56817-netty-xmldecoder-xml-external-entity-reference-vulnerability","title":"Netty XmlDecoder XML external entity reference vulnerability","severity":"high","exploited":false,"published_at":"2026-07-21T23:17:52.127+00:00","url":"https://junglewise.ai/threats/cve-2026-56817-netty-xmldecoder-xml-external-entity-reference-vulnerability"}],"vendor":{"hub":true,"name":"Netty Project","slug":"netty-project","description":"Java-based event-driven network application framework for building high-performance servers and clients.","url":"https://junglewise.ai/threats/vendors/netty-project"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":9},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":7},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":7},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":4}],"most_severe":[{"cve":"CVE-2026-47691","cvss":8.7,"epss":0.0036,"slug":"cve-2026-47691-netty-dns-cache-poisoning-via-insufficient-ns-record-bailiwick","title":"Netty DNS cache poisoning via insufficient NS record bailiwick validation","severity":"high","exploited":false,"published_at":"2026-06-12T16:16:30.31+00:00","url":"https://junglewise.ai/threats/cve-2026-47691-netty-dns-cache-poisoning-via-insufficient-ns-record-bailiwick"},{"cve":"CVE-2026-45674","cvss":8.7,"epss":0.0036,"slug":"cve-2026-45674-netty-dns-cache-poisoning-via-missing-cname-bailiwick-validation","title":"Netty DNS cache poisoning via missing CNAME bailiwick validation","severity":"high","exploited":false,"published_at":"2026-06-12T15:16:27.55+00:00","url":"https://junglewise.ai/threats/cve-2026-45674-netty-dns-cache-poisoning-via-missing-cname-bailiwick-validation"},{"cve":"CVE-2026-42578","cvss":7.5,"epss":0.0115,"slug":"cve-2026-42578-netty-http-header-injection-in-httpproxyhandler","title":"Netty HTTP header injection in HttpProxyHandler","severity":"high","exploited":false,"published_at":"2026-05-13T19:17:23.21+00:00","url":"https://junglewise.ai/threats/cve-2026-42578-netty-http-header-injection-in-httpproxyhandler"},{"cve":"CVE-2026-42587","cvss":7.5,"epss":0.0105,"slug":"cve-2026-42587-netty-denial-of-service-via-decompression-limit-bypass","title":"Netty denial of service via decompression limit bypass","severity":"high","exploited":false,"published_at":"2026-05-13T19:17:24.46+00:00","url":"https://junglewise.ai/threats/cve-2026-42587-netty-denial-of-service-via-decompression-limit-bypass"},{"cve":"CVE-2026-44893","cvss":7.5,"epss":0.0088,"slug":"cve-2026-44893-netty-memory-leak-in-haproxymessagedecoder-ssl-tlv-parsing","title":"Netty memory leak in HAProxyMessageDecoder SSL TLV parsing","severity":"high","exploited":false,"published_at":"2026-06-12T15:16:26.103+00:00","url":"https://junglewise.ai/threats/cve-2026-44893-netty-memory-leak-in-haproxymessagedecoder-ssl-tlv-parsing"},{"cve":"CVE-2026-50011","cvss":7.5,"epss":0.0085,"slug":"cve-2026-50011-netty-memory-exhaustion-in-redisarrayaggregator","title":"Netty memory exhaustion in RedisArrayAggregator","severity":"high","exploited":false,"published_at":"2026-06-12T16:16:31.313+00:00","url":"https://junglewise.ai/threats/cve-2026-50011-netty-memory-exhaustion-in-redisarrayaggregator"},{"cve":"CVE-2026-46340","cvss":7.5,"epss":0.0085,"slug":"cve-2026-46340-netty-memory-exhaustion-in-netty-transport-sctp","title":"Netty memory exhaustion in netty-transport-sctp","severity":"high","exploited":false,"published_at":"2026-06-12T15:16:27.743+00:00","url":"https://junglewise.ai/threats/cve-2026-46340-netty-memory-exhaustion-in-netty-transport-sctp"},{"cve":"CVE-2026-44890","cvss":7.5,"epss":0.0085,"slug":"cve-2026-44890-netty-memory-exhaustion-in-redisdecoder","title":"Netty memory exhaustion in RedisDecoder","severity":"high","exploited":false,"published_at":"2026-06-11T22:16:56.997+00:00","url":"https://junglewise.ai/threats/cve-2026-44890-netty-memory-exhaustion-in-redisdecoder"},{"cve":"CVE-2026-44250","cvss":7.5,"epss":0.0085,"slug":"cve-2026-44250-netty-netty-codec-redis-memory-exhaustion-in-redisarrayaggregator","title":"Netty netty-codec-redis memory exhaustion in RedisArrayAggregator","severity":"high","exploited":false,"published_at":"2026-06-11T22:16:56.857+00:00","url":"https://junglewise.ai/threats/cve-2026-44250-netty-netty-codec-redis-memory-exhaustion-in-redisarrayaggregator"},{"cve":"CVE-2026-42579","cvss":7.5,"epss":0.0085,"slug":"cve-2026-42579-netty-dns-codec-input-validation-bypass-in-dnscodecutil","title":"Netty DNS codec input validation bypass in DnsCodecUtil","severity":"high","exploited":false,"published_at":"2026-05-13T19:17:23.353+00:00","url":"https://junglewise.ai/threats/cve-2026-42579-netty-dns-codec-input-validation-bypass-in-dnscodecutil"}],"generated_at":"2026-09-26T15:07:00.181821+00:00","technologies":[{"name":"Netty Project Netty Codec HTTP","slug":"codec-http","vulnerabilities":11,"url":"https://junglewise.ai/threats/technologies/codec-http"},{"name":"Netty Project Netty Codec Redis","slug":"codec-redis","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/codec-redis"},{"name":"Netty Project Netty Incubator Codec OHTTP","slug":"incubator-codec-ohttp","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/incubator-codec-ohttp"},{"name":"Netty Project Netty netty-codec-http2","slug":"netty-codec-http2","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/netty-codec-http2"},{"name":"Netty Project Netty Codec HAProxy","slug":"codec-haproxy","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/codec-haproxy"},{"name":"Netty Project Netty Handler SSL OCSP","slug":"netty-handler-ssl-ocsp","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/netty-handler-ssl-ocsp"},{"name":"Netty Project Netty Resolver DNS","slug":"resolver-dns","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/resolver-dns"}]}