VYPR

apk package

wolfi/thingsboard-tb-mqtt-transport

pkg:apk/wolfi/thingsboard-tb-mqtt-transport

Vulnerabilities (150)

  • CVE-2026-59949MedAug 18, 2026
    affected < 4.3.1.3-r13fixed 4.3.1.3-r13

    yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInstance().hash32().hash(), XXHashFactory.nativeInstance().hash64().hash(), XXHashFact

  • CVE-2026-59903MedAug 17, 2026
    affected < 4.3.1.3-r22fixed 4.3.1.3-r22

    Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.http.cors.CorsHandler setVaryHeader replaces application Vary headers such as Authorization or Cookie with Origin, allowing a caching proxy or CDN

  • CVE-2026-59902HigAug 17, 2026
    affected < 4.3.1.3-r21fixed 4.3.1.3-r21

    Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.sctp.SctpMessageCompletionHandler limits incomplete messages and fragment counts but not maxBufferedBytes, allowing unauthenticated peers to exhau

  • CVE-2026-73508MedAug 13, 2026
    affected < 4.3.1.3-r11fixed 4.3.1.3-r11

    Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.dns.AbstractDnsRecord, io.netty.handler.codec.dns.DefaultDnsRecordDecoder.decodeRecord(), and io.netty.handler.codec.dns.DnsCodecUtil.decompressDo

  • CVE-2026-73507HigAug 13, 2026
    affected < 4.3.1.3-r7fixed 4.3.1.3-r7

    Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.xml.XmlFrameDecoder.decode() failed to preserve closing-tag parser state across invocations, so an unauthenticated remote attacker could trickle-f

  • CVE-2026-64607MedJul 31, 2026
    affected < 4.3.1.3-r19fixed 4.3.1.3-r19

    HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not affect HttpClient bas

  • CVE-2026-59898HigJul 29, 2026
    affected < 4.3.1.3-r9fixed 4.3.1.3-r9

    Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ab attacker can force WebSocket upgrade via the lax V07 (or V08) handshaker by sending `Sec-WebSocket-Version: 7` and omitting `Connection: Upgrade` / `Upgrade

  • CVE-2026-59919MedJul 29, 2026
    affected < 4.3.1.3-r11fixed 4.3.1.3-r11

    Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Final, Netty's HAProxy encoder ( HAProxyMessageEncoder ) writes AF_UNIX source and destination socket addresses into the HAProxy V1 text protocol without validating

  • CVE-2026-59901HigJul 29, 2026
    affected < 4.3.1.3-r10fixed 4.3.1.3-r10

    Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the `Bzip2Decoder` handler in Netty's compression codec pipeline is vulnerable to a denial-of-service attack through a malformed bzip2 stream that permanently c

  • CVE-2026-59900MedJul 29, 2026
    affected < 4.3.1.3-r11fixed 4.3.1.3-r11

    Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, Netty's HTTP/2-to-HTTP/1.x translation layer (`Http2StreamFrameToHttpObjectCodec` and `InboundHttp2ToHttpAdapter`) fails to deduplicate or validate `Host` heade

  • CVE-2026-59899HigJul 29, 2026
    affected < 4.3.1.3-r9fixed 4.3.1.3-r9

    Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, `HttpContentEncoder` (the superclass of the production handler `HttpContentCompressor`) maintains a per-channel `ArrayDeque` named `acceptEncoding

  • CVE-2026-56822HigJul 29, 2026
    affected < 4.3.1.3-r6fixed 4.3.1.3-r6

    Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator forwards the SslHandshakeCompletionEvent before the asynchronous OCSP validation completes. This allows the client's downstre

  • CVE-2026-56821HigJul 29, 2026
    affected < 4.3.1.3-r6fixed 4.3.1.3-r6

    Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator flags an out-of-date OCSP response but does not stop processing it, so an expired GOOD response is still reported as VALID, l

  • CVE-2026-59921MedJul 28, 2026
    affected < 4.3.1.3-r9fixed 4.3.1.3-r9

    Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, HttpPostRequestEncoder constructs multipart HTTP request bodies by directly concatenating user-supplied filenames and field names into Content-Disposition MIME

  • CVE-2026-56820HigJul 21, 2026
    affected < 4.3.1.3-r6fixed 4.3.1.3-r6

    Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final, `OcspClient` does not validate that the `CertificateID` in an OCSP response matches the requested `CertificateID`, wh

  • CVE-2026-56817CriJul 21, 2026
    affected < 4.3.1.3-r7fixed 4.3.1.3-r7

    Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, any caller that can deliver bytes to a Netty channel pipeline containing `XmlDecoder` can send XML with a

  • CVE-2026-56746MedJul 21, 2026
    affected < 4.3.1.3-r9fixed 4.3.1.3-r9

    Netty is a network application framework for development of protocol servers and clients. Versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, are vulnerable to security control bypass during the origin evaluation process. CorsHandler provides a shortC

  • CVE-2026-56745HigJul 21, 2026
    affected < 4.3.1.3-r9fixed 4.3.1.3-r9

    Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, the `SpdyHttpDecoder` handler in Netty's SPDY-to-HTTP codec allocates a pooled `ByteBuf` when processing a

  • CVE-2026-55851HigJul 21, 2026
    affected < 4.3.1.3-r11fixed 4.3.1.3-r11

    Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final up to (but not including) 4.2.16.Final, and 4.1.0.Final up to (but not including) 4.1.135, the `HAProxyMessageDecoder` in Netty's `codec-haproxy` module performs prot

  • CVE-2026-55833HigJul 21, 2026
    affected < 4.3.1.3-r9fixed 4.3.1.3-r9

    Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has exceeded `maxHeaderSize` and marked the

Page 1 of 8