{"schema_version":1,"title":"Netty vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 43 vulnerabilities in Netty: 8 in the last 7 days and 31 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-100663, was published on 26 September 2026. 5 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/netty","json_url":"https://junglewise.ai/threats/vendors/netty.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/netty","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":29,"all_time":43,"critical":0,"exploited":0,"last_7_days":8,"last_30_days":21,"last_90_days":31,"last_365_days":42},"latest":[{"cve":"CVE-2026-100663","cvss":7.5,"slug":"cve-2026-100663-netty-s-http-3-codec-io-netty-netty-codec-http3-from-4-2-2-final","title":"Netty HTTP/3 codec CONNECT authority-form parsing bypass","severity":"high","exploited":false,"published_at":"2026-09-26T14:16:49.4+00:00","url":"https://junglewise.ai/threats/cve-2026-100663-netty-s-http-3-codec-io-netty-netty-codec-http3-from-4-2-2-final"},{"cve":"CVE-2026-100662","cvss":7.5,"slug":"cve-2026-100662-netty-s-http-3-codec-io-netty-netty-codec-http3-versions-4-2-0","title":"Netty HTTP/3 QPACK encoder-stream unbounded memory consumption","severity":"high","exploited":false,"published_at":"2026-09-26T14:16:49.257+00:00","url":"https://junglewise.ai/threats/cve-2026-100662-netty-s-http-3-codec-io-netty-netty-codec-http3-versions-4-2-0"},{"cve":"CVE-2026-100661","cvss":7.5,"slug":"cve-2026-100661-netty-s-http-3-codec-io-netty-netty-codec-http3-versions-4-2-0","title":"Netty HTTP/3 codec QPACK prefixed-integer denial-of-service","severity":"high","exploited":false,"published_at":"2026-09-26T14:16:49.11+00:00","url":"https://junglewise.ai/threats/cve-2026-100661-netty-s-http-3-codec-io-netty-netty-codec-http3-versions-4-2-0"},{"cve":"CVE-2026-100660","cvss":7.5,"slug":"cve-2026-100660-netty-s-http-3-codec-io-netty-netty-codec-http3-from-4-2-0-final","title":"Netty netty-codec-http3 unbounded QPACK encoder memory retention","severity":"high","exploited":false,"published_at":"2026-09-26T14:16:48.97+00:00","url":"https://junglewise.ai/threats/cve-2026-100660-netty-s-http-3-codec-io-netty-netty-codec-http3-from-4-2-0-final"},{"cve":"CVE-2026-100658","cvss":5.3,"slug":"cve-2026-100658-netty-io-netty-netty-codec-http-contains-an-unbounded-per","title":"Netty unbounded queue denial of service in WebSocketServerExtensionHandler","severity":"medium","exploited":false,"published_at":"2026-09-26T14:16:48.687+00:00","url":"https://junglewise.ai/threats/cve-2026-100658-netty-io-netty-netty-codec-http-contains-an-unbounded-per"},{"cve":"CVE-2026-100657","cvss":7.5,"slug":"cve-2026-100657-netty-s-stomp-codec-io-netty-netty-codec-stomp-contains-a","title":"Netty STOMP codec ByteBuf leak in StompSubframeDecoder","severity":"high","exploited":false,"published_at":"2026-09-26T14:16:48.54+00:00","url":"https://junglewise.ai/threats/cve-2026-100657-netty-s-stomp-codec-io-netty-netty-codec-stomp-contains-a"},{"cve":"CVE-2026-100656","cvss":7.5,"slug":"cve-2026-100656-netty-io-netty-netty-codec-http-contains-an-unbounded-per","title":"Netty HttpServerCodec unbounded queue growth via HTTP/1.1 pipelining","severity":"high","exploited":false,"published_at":"2026-09-26T14:16:48.39+00:00","url":"https://junglewise.ai/threats/cve-2026-100656-netty-io-netty-netty-codec-http-contains-an-unbounded-per"},{"cve":"CVE-2026-100655","cvss":7.5,"slug":"cve-2026-100655-netty-io-netty-netty-codec-http-versions-up-to-and-including-4-1","title":"Netty netty-codec-http denial of service in SpdySessionHandler","severity":"high","exploited":false,"published_at":"2026-09-26T14:16:48.243+00:00","url":"https://junglewise.ai/threats/cve-2026-100655-netty-io-netty-netty-codec-http-versions-up-to-and-including-4-1"},{"cve":"CVE-2026-93562","cvss":6.5,"epss":0.0058,"slug":"cve-2026-93562-a-flaw-was-found-in-netty-s-http-1-decoder-incomplete-validation","title":"Netty HTTP/1 decoder request smuggling","severity":"medium","exploited":false,"published_at":"2026-09-18T21:18:46.977+00:00","url":"https://junglewise.ai/threats/cve-2026-93562-a-flaw-was-found-in-netty-s-http-1-decoder-incomplete-validation"},{"cve":"CVE-2026-93569","cvss":8.2,"epss":0.007,"slug":"cve-2026-93569-netty-http-1-to-http-2-conversion-authority-mismatch","title":"Netty HTTP/1 to HTTP/2 conversion authority mismatch","severity":"high","exploited":false,"published_at":"2026-09-18T15:17:20.743+00:00","url":"https://junglewise.ai/threats/cve-2026-93569-netty-http-1-to-http-2-conversion-authority-mismatch"},{"cve":"CVE-2026-93566","cvss":6.5,"epss":0.0064,"slug":"cve-2026-93566-netty-http-request-smuggling-via-control-characters-in-chunk-size","title":"Netty HTTP request smuggling via control characters in chunk size","severity":"medium","exploited":false,"published_at":"2026-09-18T15:17:20.29+00:00","url":"https://junglewise.ai/threats/cve-2026-93566-netty-http-request-smuggling-via-control-characters-in-chunk-size"},{"cve":"CVE-2026-93565","cvss":7.5,"epss":0.0064,"slug":"cve-2026-93565-netty-rtspdecoder-method-token-smuggling-in-rtsp-parsing","title":"Netty RtspDecoder method-token smuggling in RTSP parsing","severity":"high","exploited":false,"published_at":"2026-09-18T15:17:20.093+00:00","url":"https://junglewise.ai/threats/cve-2026-93565-netty-rtspdecoder-method-token-smuggling-in-rtsp-parsing"},{"cve":"CVE-2026-93564","cvss":7.5,"epss":0.0079,"slug":"cve-2026-93564-netty-reference-count-leak-in-haproxy-proxy-v2-decoder","title":"Netty reference-count leak in HAProxy PROXY-v2 decoder","severity":"high","exploited":false,"published_at":"2026-09-18T15:17:19.943+00:00","url":"https://junglewise.ai/threats/cve-2026-93564-netty-reference-count-leak-in-haproxy-proxy-v2-decoder"},{"cve":"CVE-2026-93558","cvss":7.5,"epss":0.0079,"slug":"cve-2026-93558-netty-websocketserverextensionhandler-denial-of-service","title":"Netty WebSocketServerExtensionHandler denial of service","severity":"high","exploited":false,"published_at":"2026-09-18T15:17:19.59+00:00","url":"https://junglewise.ai/threats/cve-2026-93558-netty-websocketserverextensionhandler-denial-of-service"},{"cve":"CVE-2026-93560","cvss":7.5,"epss":0.0058,"slug":"cve-2026-93560-netty-stomp-codec-integer-truncation-denial-of-service","title":"Netty STOMP codec integer truncation denial of service","severity":"high","exploited":false,"published_at":"2026-09-18T14:19:08.21+00:00","url":"https://junglewise.ai/threats/cve-2026-93560-netty-stomp-codec-integer-truncation-denial-of-service"},{"cve":"CVE-2026-93492","cvss":5.3,"epss":0.0064,"slug":"cve-2026-93492-netty-http-2-hpackencoder-denial-of-service","title":"Netty HTTP/2 HpackEncoder Denial of Service","severity":"medium","exploited":false,"published_at":"2026-09-18T13:18:38.877+00:00","url":"https://junglewise.ai/threats/cve-2026-93492-netty-http-2-hpackencoder-denial-of-service"},{"cve":"CVE-2026-93491","cvss":7.5,"epss":0.0087,"slug":"cve-2026-93491-netty-httpservercodec-denial-of-service-via-http-request","title":"Netty HttpServerCodec denial of service via HTTP request pipelining","severity":"high","exploited":false,"published_at":"2026-09-18T13:18:38.723+00:00","url":"https://junglewise.ai/threats/cve-2026-93491-netty-httpservercodec-denial-of-service-via-http-request"},{"cve":"CVE-2026-93488","cvss":7.5,"epss":0.007,"slug":"cve-2026-93488-netty-spdysessionhandler-unbounded-stream-denial-of-service","title":"Netty SpdySessionHandler unbounded stream denial of service","severity":"high","exploited":false,"published_at":"2026-09-18T12:17:30.667+00:00","url":"https://junglewise.ai/threats/cve-2026-93488-netty-spdysessionhandler-unbounded-stream-denial-of-service"},{"cve":"CVE-2026-93578","cvss":5.9,"epss":0.0029,"slug":"cve-2026-93578-netty-ocsp-client-eku-verification-bypass","title":"Netty OCSP Client EKU verification bypass","severity":"medium","exploited":false,"published_at":"2026-09-18T11:17:22.17+00:00","url":"https://junglewise.ai/threats/cve-2026-93578-netty-ocsp-client-eku-verification-bypass"},{"cve":"CVE-2026-93575","cvss":7.5,"epss":0.0066,"slug":"cve-2026-93575-a-flaw-was-found-in-netty-s-mqttdecoder-an-unauthenticated-remote","title":"Netty MqttDecoder MQTT packet validation bypass","severity":"high","exploited":false,"published_at":"2026-09-18T11:17:22.033+00:00","url":"https://junglewise.ai/threats/cve-2026-93575-a-flaw-was-found-in-netty-s-mqttdecoder-an-unauthenticated-remote"},{"cve":"CVE-2026-89044","cvss":6.5,"epss":0.0043,"slug":"cve-2026-89044-netty-http-transfer-encoding-request-smuggling","title":"Netty HTTP Transfer-Encoding request smuggling","severity":"medium","exploited":false,"published_at":"2026-09-10T18:18:16.243+00:00","url":"https://junglewise.ai/threats/cve-2026-89044-netty-http-transfer-encoding-request-smuggling"},{"cve":"CVE-2026-76816","cvss":3.5,"epss":0.0027,"slug":"cve-2026-76816-netty-mqttencoder-null-byte-injection-in-mqtt-fields","title":"Netty MqttEncoder null byte injection in MQTT fields","severity":"low","exploited":false,"published_at":"2026-08-24T20:17:19.477+00:00","url":"https://junglewise.ai/threats/cve-2026-76816-netty-mqttencoder-null-byte-injection-in-mqtt-fields"},{"cve":"CVE-2026-62243","cvss":7.5,"epss":0.0025,"slug":"cve-2026-62243-netty-tls-hostname-verification-bypass-in-openssl-client","title":"Netty TLS hostname verification bypass in OpenSSL client","severity":"high","exploited":false,"published_at":"2026-08-22T13:16:39.687+00:00","url":"https://junglewise.ai/threats/cve-2026-62243-netty-tls-hostname-verification-bypass-in-openssl-client"},{"cve":"CVE-2026-63124","cvss":7.5,"slug":"cve-2026-63124-netty-netty-incubator-codec-bhttp-infinite-loop-in-field-section","title":"Netty netty-incubator-codec-bhttp infinite loop in field section parser","severity":"high","exploited":false,"published_at":"2026-08-20T18:43:25+00:00","url":"https://junglewise.ai/threats/cve-2026-63124-netty-netty-incubator-codec-bhttp-infinite-loop-in-field-section"},{"cve":"CVE-2026-61799","cvss":5.3,"slug":"cve-2026-61799-netty-binary-http-parser-integer-overflow-in-varint-parsing","title":"Netty Binary HTTP parser integer overflow in varint parsing","severity":"medium","exploited":false,"published_at":"2026-08-20T18:43:21+00:00","url":"https://junglewise.ai/threats/cve-2026-61799-netty-binary-http-parser-integer-overflow-in-varint-parsing"}],"vendor":{"hub":true,"name":"Netty","slug":"netty","homepage":"https://netty.io/","description":"An open-source asynchronous event-driven network application framework for rapid development of maintainable high-performance protocol servers and clients.","url":"https://junglewise.ai/threats/vendors/netty"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":5},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":12},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":8}],"most_severe":[{"cve":"CVE-2026-47691","cvss":8.7,"epss":0.0036,"slug":"cve-2026-47691-netty-dns-cache-poisoning-via-insufficient-ns-record-bailiwick","title":"Netty DNS cache poisoning via insufficient NS record bailiwick validation","severity":"high","exploited":false,"published_at":"2026-06-12T16:16:30.31+00:00","url":"https://junglewise.ai/threats/cve-2026-47691-netty-dns-cache-poisoning-via-insufficient-ns-record-bailiwick"},{"cve":"CVE-2026-45674","cvss":8.7,"epss":0.0036,"slug":"cve-2026-45674-netty-dns-cache-poisoning-via-missing-cname-bailiwick-validation","title":"Netty DNS cache poisoning via missing CNAME bailiwick validation","severity":"high","exploited":false,"published_at":"2026-06-12T15:16:27.55+00:00","url":"https://junglewise.ai/threats/cve-2026-45674-netty-dns-cache-poisoning-via-missing-cname-bailiwick-validation"},{"cve":"CVE-2026-93569","cvss":8.2,"epss":0.007,"slug":"cve-2026-93569-netty-http-1-to-http-2-conversion-authority-mismatch","title":"Netty HTTP/1 to HTTP/2 conversion authority mismatch","severity":"high","exploited":false,"published_at":"2026-09-18T15:17:20.743+00:00","url":"https://junglewise.ai/threats/cve-2026-93569-netty-http-1-to-http-2-conversion-authority-mismatch"},{"cve":"CVE-2026-61798","cvss":8.1,"slug":"cve-2026-61798-netty-netty-incubator-codec-ohttp-hpke-private-key-exposure-in","title":"Netty netty-incubator-codec-ohttp HPKE private key exposure in toString()","severity":"high","exploited":false,"published_at":"2026-08-20T18:43:17+00:00","url":"https://junglewise.ai/threats/cve-2026-61798-netty-netty-incubator-codec-ohttp-hpke-private-key-exposure-in"},{"cve":"CVE-2019-16869","cvss":7.5,"epss":0.0842,"slug":"cve-2019-16869-netty-http-request-smuggling-via-header-whitespace-mishandling","title":"Netty HTTP request smuggling via header whitespace mishandling","severity":"high","exploited":false,"published_at":"2019-10-11T18:41:23+00:00","url":"https://junglewise.ai/threats/cve-2019-16869-netty-http-request-smuggling-via-header-whitespace-mishandling"},{"cve":"CVE-2026-93491","cvss":7.5,"epss":0.0087,"slug":"cve-2026-93491-netty-httpservercodec-denial-of-service-via-http-request","title":"Netty HttpServerCodec denial of service via HTTP request pipelining","severity":"high","exploited":false,"published_at":"2026-09-18T13:18:38.723+00:00","url":"https://junglewise.ai/threats/cve-2026-93491-netty-httpservercodec-denial-of-service-via-http-request"},{"cve":"CVE-2026-42579","cvss":7.5,"epss":0.0085,"slug":"cve-2026-42579-netty-dns-codec-input-validation-bypass-in-dnscodecutil","title":"Netty DNS codec input validation bypass in DnsCodecUtil","severity":"high","exploited":false,"published_at":"2026-05-13T19:17:23.353+00:00","url":"https://junglewise.ai/threats/cve-2026-42579-netty-dns-codec-input-validation-bypass-in-dnscodecutil"},{"cve":"CVE-2026-93564","cvss":7.5,"epss":0.0079,"slug":"cve-2026-93564-netty-reference-count-leak-in-haproxy-proxy-v2-decoder","title":"Netty reference-count leak in HAProxy PROXY-v2 decoder","severity":"high","exploited":false,"published_at":"2026-09-18T15:17:19.943+00:00","url":"https://junglewise.ai/threats/cve-2026-93564-netty-reference-count-leak-in-haproxy-proxy-v2-decoder"},{"cve":"CVE-2026-93558","cvss":7.5,"epss":0.0079,"slug":"cve-2026-93558-netty-websocketserverextensionhandler-denial-of-service","title":"Netty WebSocketServerExtensionHandler denial of service","severity":"high","exploited":false,"published_at":"2026-09-18T15:17:19.59+00:00","url":"https://junglewise.ai/threats/cve-2026-93558-netty-websocketserverextensionhandler-denial-of-service"},{"cve":"CVE-2026-93488","cvss":7.5,"epss":0.007,"slug":"cve-2026-93488-netty-spdysessionhandler-unbounded-stream-denial-of-service","title":"Netty SpdySessionHandler unbounded stream denial of service","severity":"high","exploited":false,"published_at":"2026-09-18T12:17:30.667+00:00","url":"https://junglewise.ai/threats/cve-2026-93488-netty-spdysessionhandler-unbounded-stream-denial-of-service"}],"generated_at":"2026-09-27T03:07:00.185062+00:00","technologies":[{"name":"Netty","slug":"netty","vulnerabilities":20,"url":"https://junglewise.ai/threats/technologies/netty"},{"name":"Netty Codec HTTP/3","slug":"codec-http-3","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/codec-http-3"},{"name":"Netty-Codec-Http3","slug":"netty-codec-http3","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/netty-codec-http3"},{"name":"Netty-Codec-Http","slug":"netty-netty-codec-http","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/netty-netty-codec-http"},{"name":"Netty-Resolver-Dns","slug":"netty-resolver-dns","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/netty-resolver-dns"}]}