io.netty:netty-codec-http
Maven24 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting io.netty:netty-codec-httppage 1 of 1
- CVE-2019-20444CRITICALCVSS 9.1EG 9.1fixed in 4.1.442020-01-29
vulnerable: 4.0.0.Alpha1 ... 4.1.9.Final (137 versions)
HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an "invalid fold."
- CVE-2021-21290MEDIUMCVSS 5.5EG 5.5fixed in 4.1.59.Final2021-02-08
vulnerable: 4.0.0.Final ... 4.1.9.Final (132 versions)
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty before version 4.1.59.Final there is a vulnerability on Unix-like …
- CVE-2021-43797MEDIUMCVSS 6.5EG 6.5fixed in 4.1.71.Final2021-12-09
vulnerable: 4.0.0.Final ... 4.1.9.Final (144 versions)
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. Netty prior to version 4.1.71.Final skips control chars when they are present at the beg…
- CVE-2022-24823MEDIUMCVSS 5.5EG 5.5fixed in 4.1.77.Final2022-05-06
vulnerable: 4.0.0.Alpha1 ... 4.1.9.Final (170 versions)
Netty is an open-source, asynchronous event-driven network application framework. The package `io.netty:netty-codec-http` prior to version 4.1.77.Final contains an insufficient fix for CVE-2021-21290. When Netty's multipart decoders are us…
- CVE-2022-41915MEDIUMCVSS 6.5EG 6.5fixed in 4.1.86.Final2022-12-13
vulnerable: 4.1.83.Final, 4.1.84.Final, 4.1.85.Final
Netty project is an event-driven asynchronous network application framework. Starting in version 4.1.83.Final and prior to 4.1.86.Final, when calling `DefaultHttpHeadesr.set` with an _iterator_ of values, header value validation was not pe…
- CVE-2024-29025MEDIUMCVSS 5.3EG 5.3fixed in 4.1.108.Final2024-03-25
vulnerable: 4.0.0.Alpha1 ... 4.1.99.Final (201 versions)
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `HttpPostRequestDecoder` can be tricked to accumulate data. While the decoder can st…
- CVE-2025-58056HIGHCVSS 7.5EG 7.5fixed in 4.1.125.Final or 4.2.5.Final, by version range2025-09-03
vulnerable: 4.2.0.Alpha1 ... 4.2.4.Final (15 versions)
Netty is an asynchronous event-driven network application framework for development of maintainable high performance protocol servers and clients. In versions 4.1.124.Final, and 4.2.0.Alpha3 through 4.2.4.Final, Netty incorrectly accepts s…
- CVE-2025-67735MEDIUMCVSS 6.5EG 6.5fixed in 4.2.8.Final or 4.1.129.Final, by version range2025-12-16
vulnerable: 4.0.0.Alpha1 ... 4.1.99.Final (222 versions)
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a re…
- CVE-2026-33870HIGHCVSS 7.5EG 7.5fixed in 4.1.132.Final or 4.2.10.Final, by version range2026-03-27
vulnerable: 4.2.0.Alpha1 ... 4.2.9.Final (20 versions)
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smu…
- CVE-2026-41417MEDIUMCVSS 5.3EG 5.3fixed in 4.1.133.Final or 4.2.13.Final, by version range2026-05-06
vulnerable: 4.2.0.Alpha1 ... 4.2.9.Final (23 versions)
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would bre…
- CVE-2026-42580MEDIUMCVSS 6.5EG 6.5fixed in 4.2.13.Final or 4.1.133.Final, by version range2026-05-13
vulnerable: 4.0.0.Alpha1 ... 4.1.99.Final (226 versions)
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Fina…
- CVE-2026-42581CRITICALCVSS 9.8EG 9.8fixed in 4.2.13.Final or 4.1.133.Final, by version range2026-05-13
vulnerable: 4.0.0.Alpha1 ... 4.1.99.Final (226 versions)
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-…
- CVE-2026-42584CRITICALCVSS 9.1EG 9.1fixed in 4.2.13.Final or 4.1.133.Final, by version range2026-05-13
vulnerable: 4.0.0.Alpha1 ... 4.1.99.Final (226 versions)
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If th…
- CVE-2026-42585MEDIUMCVSS 6.5EG 6.5fixed in 4.2.13.Final or 4.1.133.Final, by version range2026-05-13
vulnerable: 4.0.0.Alpha1 ... 4.1.99.Final (226 versions)
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.…
- CVE-2026-42587HIGHCVSS 7.5EG 7.5fixed in 4.2.13.Final or 4.1.133.Final, by version range2026-05-13
vulnerable: 4.0.0.Alpha1 ... 4.1.99.Final (226 versions)
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb atta…
- CVE-2026-50020MEDIUMCVSS 5.3EG 5.3fixed in 4.2.15.Final or 4.1.135.Final, by version range2026-06-12
vulnerable: 4.0.0.Alpha1 ... 4.1.99.Final (228 versions)
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, before reading the first request-line, `HttpObjectDecoder` skips every byte for which `Character.is…
- CVE-2026-55831HIGHCVSS 7.5EG 7.5fixed in 4.2.16.Final or 4.1.136.Final, by version range2026-07-20
vulnerable: 4.1.0.Final ... 4.1.99.Final (136 versions)
Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length lim…
- CVE-2026-55833HIGHCVSS 7.5EG 7.5fixed in 4.2.16.Final or 4.1.136.Final, by version range2026-07-20
vulnerable: 4.1.0.Final ... 4.1.99.Final (136 versions)
Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has…
- CVE-2026-56745HIGHCVSS 7.5EG 7.5fixed in 4.2.16.Final or 4.1.136.Final, by version range2026-07-21
vulnerable: 4.1.0.Final ... 4.1.99.Final (136 versions)
Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, the `SpdyHttpDecoder` handler in Netty's SPDY-to-HTTP codec alloc…
- CVE-2026-56746MEDIUMCVSS 6.5EG 6.5fixed in 4.2.16.Final or 4.1.136.Final, by version range2026-07-21
vulnerable: 4.0.0.Alpha1 ... 4.1.99.Final (229 versions)
Netty is a network application framework for development of protocol servers and clients. Versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, are vulnerable to security control bypass during the origin evaluati…
- CVE-2026-59898HIGHCVSS 7.5EG 7.5fixed in 4.2.16.Final or 4.1.136.Final, by version range2026-07-22
vulnerable: 4.0.0.Alpha1 ... 4.1.99.Final (229 versions)
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ab attacker can force WebSocket upgrade via the lax V07 (or V08) handshaker by sending `Sec-WebSocket-Version: 7` and …
- CVE-2026-59899HIGHCVSS 7.5EG 7.5fixed in 4.2.16.Final or 4.1.136.Final, by version range2026-07-22
vulnerable: 4.0.0.Alpha1 ... 4.1.99.Final (229 versions)
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, `HttpContentEncoder` (the superclass of the production handler `HttpContentCompressor`) maintains a per-channel `ArrayD…
- CVE-2026-59903HIGHCVSS 7.5EG 7.5fixed in 4.2.17.Final or 4.1.137.Final, by version range2026-08-17
vulnerable: 4.0.0.Alpha1 ... 4.1.99.Final (230 versions)
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.http.cors.CorsHandler setVaryHeader replaces application Vary headers such as Authorization or Cookie wit…
- CVE-2026-59921MEDIUMCVSS 6.5EG 6.5fixed in 4.2.16.Final or 4.1.136.Final, by version range2026-07-22
vulnerable: 4.0.0.Alpha1 ... 4.1.99.Final (229 versions)
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, HttpPostRequestEncoder constructs multipart HTTP request bodies by directly concatenating user-supplied filenames and f…
Check whether io.netty:netty-codec-http is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for io.netty:netty-codec-http CVEs against the assets you own.
Book a Demo →