io.netty:netty-handler
Maven13 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting io.netty:netty-handlerpage 1 of 1
- CVE-2014-3488MEDIUMCVSS v2 5.0EG 5.0fixed in 3.9.22014-07-31
The SslHandler in Netty before 3.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted SSLv2Hello message.
- CVE-2016-4970HIGHCVSS 7.5EG 7.5fixed in 4.0.37.Final or 4.1.1.Final, by version range2017-04-13
vulnerable: 4.1.0.Beta1 ... 4.1.0.Final (16 versions)
handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (infinite loop).
- CVE-2019-20445CRITICALCVSS 9.1EG 9.1fixed in 4.1.452020-01-29
vulnerable: 4.0.0.Final ... 4.1.9.Final (118 versions)
HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.
- CVE-2020-11612HIGHCVSS 7.5EG 7.5fixed in 4.1.462020-04-07
vulnerable: 4.1.0.Final ... 4.1.9.Final (46 versions)
The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send a large ZlibEncoded byte stream to the Netty server, forcing the server to allocate all of…
- CVE-2020-7238HIGHCVSS 7.5EG 7.5fixed in 4.1.452020-01-27
vulnerable: 4.1.43.Final, 4.1.44.Final
Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line) and a later Content-Length header. This issue exists because of an incomplete fix for CVE…
- CVE-2023-34462MEDIUMCVSS 6.5EG 6.5fixed in 4.1.94.Final2023-06-22
vulnerable: 4.0.0.Alpha1 ... 4.1.93.Final (187 versions)
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `SniHandler` can allocate up to 16MB of heap for each channel during the TLS handsha…
- CVE-2023-4586HIGHCVSS 7.4EG 7.42023-10-04
vulnerable: 4.1.0.Final ... 4.1.99.Final (100 versions)
A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS, possibly resulting in a man-in-the-middle (MITM) attack.
- CVE-2025-24970HIGHCVSS 7.5EG 7.5fixed in 4.1.118.Final2025-02-10
vulnerable: 4.1.100.Final ... 4.1.99.Final (27 versions)
Netty, an asynchronous, event-driven network application framework, has a vulnerability starting in version 4.1.91.Final and prior to version 4.1.118.Final. When a special crafted packet is received via SslHandler it doesn't correctly hand…
- CVE-2026-44249HIGHCVSS 8.1EG 8.1fixed in 4.2.15.Final or 4.1.135.Final, by version range2026-06-08
vulnerable: 4.0.0.Alpha1 ... 4.1.99.Final (228 versions)
Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation in …
- CVE-2026-45416HIGHCVSS 7.5EG 7.5fixed in 4.2.15.Final or 4.1.135.Final, by version range2026-06-08
vulnerable: 4.0.0.Alpha1 ... 4.1.99.Final (228 versions)
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SslClientHelloHandler.decode() reads the 24-bit TLS handshake length and, when the ClientHello does…
- CVE-2026-50010HIGHCVSS 7.5EG 7.5fixed in 4.2.15.Final or 4.1.135.Final, by version range2026-06-12
vulnerable: 4.0.0.Alpha1 ... 4.1.99.Final (228 versions)
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SimpleTrustManagerFactory.engineGetTrustManagers() and related paths wrap any user-supplied plain X…
- CVE-2026-75595CRITICALCVSS 9.1EG 9.1fixed in 4.2.17.Final or 4.1.137.Final, by version range2026-08-19
vulnerable: 4.0.0.Alpha1 ... 4.1.99.Final (230 versions)
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.handler.ssl.SslClientHelloHandler#decode checks the wrong offset before reading the four-byte TLS handshake header, so a…
- CVE-2026-75596HIGHCVSS 7.5EG 7.5fixed in 4.2.17.Final or 4.1.137.Final, by version range2026-08-19
vulnerable: 4.0.0.Alpha1 ... 4.1.99.Final (230 versions)
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, the default io.netty.handler.ssl.SniHandler constructors use the pre-handshake ClientHello aggregation path in handler/src/main/…
Check whether io.netty:netty-handler is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for io.netty:netty-handler CVEs against the assets you own.
Book a Demo →