VYPR

io.netty.handler.codec.xml.XmlFrameDecoder

by Netty

Source repositories

CVEs (1)

  • CVE-2026-73507HigAug 13, 2026
    risk 0.42cvss 7.5epss 0.01

    Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.xml.XmlFrameDecoder.decode() failed to preserve closing-tag parser state across invocations, so an unauthenticated remote attacker could…