VYPR

rpm package

opensuse/netty&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/netty&distro=openSUSE%20Tumbleweed

Vulnerabilities (102)

  • CVE-2026-33870HigMar 27, 2026
    affected < 4.1.132-1.1fixed 4.1.132-1.1

    Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final an

  • CVE-2025-67735MedDec 16, 2025
    affected < 4.1.130-1.1fixed 4.1.130-1.1

    Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling wh

  • CVE-2025-59419MedOct 15, 2025
    affected < 4.1.128-1.1fixed 4.1.128-1.1

    Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.128.Final and 4.2.7.Final, the SMTP codec in Netty contains an SMTP command injection vulnerability due to insufficient input validation for Carriage Return (\r) and Line Feed (\n) char

  • CVE-2025-58057HigSep 4, 2025
    affected < 4.1.126-1.1fixed 4.1.126-1.1

    Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In netty-codec-compression versions 4.1.124.Final and below, and netty-codec versions 4.2.4.Final and below, when supplied with s

  • CVE-2025-58056HigSep 3, 2025
    affected < 4.1.126-1.1fixed 4.1.126-1.1

    Netty is an asynchronous event-driven network application framework for development of maintainable high performance protocol servers and clients. In versions 4.1.124.Final, and 4.2.0.Alpha3 through 4.2.4.Final, Netty incorrectly accepts standalone newline characters (LF) as a ch

  • CVE-2025-55163HigAug 13, 2025
    affected < 4.1.124-1.1fixed 4.1.124-1.1

    Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.124.Final and 4.2.4.Final, Netty is vulnerable to MadeYouReset DDoS. This is a logical vulnerability in the HTTP/2 protocol, that uses malformed HTTP/2 control frames in order to break the

  • CVE-2025-25193MedFeb 10, 2025
    affected < 4.1.118-1.1fixed 4.1.118-1.1

    Netty, an asynchronous, event-driven network application framework, has a vulnerability in versions up to and including 4.1.118.Final. An unsafe reading of environment file could potentially cause a denial of service in Netty. When loaded on an Windows application, Netty attempts

  • CVE-2025-24970HigFeb 10, 2025
    affected < 4.1.118-1.1fixed 4.1.118-1.1

    Netty, an asynchronous, event-driven network application framework, has a vulnerability starting in version 4.1.91.Final and prior to version 4.1.118.Final. When a special crafted packet is received via SslHandler it doesn't correctly handle validation of such a packet in all cas

  • CVE-2024-47535MedNov 12, 2024
    affected < 4.1.115-1.1fixed 4.1.115-1.1

    Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. An unsafe reading of environment file could potentially cause a denial of service in Netty. When loaded on an Windows application

  • CVE-2024-29025MedMar 25, 2024
    affected < 4.1.114-1.1fixed 4.1.114-1.1

    Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `HttpPostRequestDecoder` can be tricked to accumulate data. While the decoder can store items on the disk if configured so, t

  • CVE-2023-44487HigKEVOct 10, 2023
    affected < 4.1.114-1.1fixed 4.1.114-1.1

    The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

  • CVE-2023-34462MedJun 22, 2023
    affected < 4.1.114-1.1fixed 4.1.114-1.1

    Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `SniHandler` can allocate up to 16MB of heap for each channel during the TLS handshake. When the handler or the channel does

  • CVE-2022-41915MedDec 13, 2022
    affected < 4.1.114-1.1fixed 4.1.114-1.1

    Netty project is an event-driven asynchronous network application framework. Starting in version 4.1.83.Final and prior to 4.1.86.Final, when calling `DefaultHttpHeadesr.set` with an _iterator_ of values, header value validation was not performed, allowing malicious header values

  • CVE-2022-41881MedDec 12, 2022
    affected < 4.1.114-1.1fixed 4.1.114-1.1

    Netty project is an event-driven asynchronous network application framework. In versions prior to 4.1.86.Final, a StackOverflowError can be raised when parsing a malformed crafted message due to an infinite recursion. This issue is patched in version 4.1.86.Final. There is no wor

  • CVE-2022-24823MedMay 6, 2022
    affected < 4.1.114-1.1fixed 4.1.114-1.1

    Netty is an open-source, asynchronous event-driven network application framework. The package `io.netty:netty-codec-http` prior to version 4.1.77.Final contains an insufficient fix for CVE-2021-21290. When Netty's multipart decoders are used local information disclosure can occur

  • CVE-2021-43797MedDec 9, 2021
    affected < 4.1.72-1.1fixed 4.1.72-1.1

    Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. Netty prior to version 4.1.71.Final skips control chars when they are present at the beginning / end of the header name. It shoul

  • CVE-2021-37137HigOct 19, 2021
    affected < 4.1.114-1.1fixed 4.1.114-1.1

    The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable chunks until the whole chunk was received which may lead to excessive memory usage as well. This vulnerability can be tr

  • CVE-2021-37136HigOct 19, 2021
    affected < 4.1.114-1.1fixed 4.1.114-1.1

    The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack

  • CVE-2021-21409MedMar 30, 2021
    affected < 4.1.114-1.1fixed 4.1.114-1.1

    Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.61.Final there is a vulnerability that enables request smug

  • CVE-2021-21295MedMar 9, 2021
    affected < 4.1.60-1.4fixed 4.1.60-1.4

    Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.60.Final there is a vulnerability that enables request smug

Page 5 of 6