|
Posted
7 days
ago
by
normanmaurer
We are happy to announce the release of netty 4.1.137.Final. This is a bug-fix and security release.
We strongly recommend upgrading to this version to get the following security fixes:
CVE-2026-XXXXX : algorithm inefficiency in
... [More]
io.netty:netty-handler
CVE-2026-XXXXX : improper NUL byte neutrolization in io.netty:netty-codec-socks
CVE-2026-XXXXX : SNI bypass in io.netty:netty-handler
CVE-2026-59902 : memory exhaustion in io.netty:netty-transport-sctp
CVE-2026-59903 : cache poisoning & info disclosure in io.netty:netty-codec-http
CVE-2026-XXXXX : validation bypass in io.netty:netty-codec-mqtt
CVE-2026-XXXXX : improper hostname verification in io.netty:netty-handler
Other significant changes are:
Auto-port 4.1: AsciiString.cached(String) should sanitize the provided String (#13749) by @netty-project-bot in https://github.com/netty/netty/pull/17069
AsciiString.cached(String) should sanitize the provided String (#13749) (#17007) by @normanmaurer in https://github.com/netty/netty/pull/17075
Fix AsciiString.cached(String) performance regression (#17074)...
[Less]
|
|
Posted
9 days
ago
by
chrisvest
We are happy to announce the release of netty 4.2.16.Final. This is a bug-fix and security release.
We strongly recommend upgrading to this version to get the following security fixes:
CVE-2026-XXXXX : algorithm inefficiency in
... [More]
io.netty:netty-handler
CVE-2026-XXXXX : improper NUL byte neutrolization in io.netty:netty-codec-socks
CVE-2026-XXXXX : SNI bypass in io.netty:netty-handler
CVE-2026-59902 : memory exhaustion in io.netty:netty-transport-sctp
CVE-2026-59903 : cache poisoning & info disclosure in io.netty:netty-codec-http
CVE-2026-XXXXX : validation bypass in io.netty:netty-codec-mqtt
CVE-2026-XXXXX : improper hostname verification in io.netty:netty-handler
Other significant changes are:
AsciiString.cached(String) should sanitize the provided String #17007
Fix AsciiString.cached(String) performance regression #17074
SslHandler: Fix possible buffer leak when an OOME is thrown during allocation #17059
Add HttpContentCompressor constructor with ability to...
[Less]
|
|
Posted
9 days
ago
by
chrisvest
We are happy to announce the release of netty 4.2.17.Final. This is a bug-fix and security release.
We strongly recommend upgrading to this version to get the following security fixes:
CVE-2026-XXXXX : algorithm inefficiency in
... [More]
io.netty:netty-handler
CVE-2026-XXXXX : improper NUL byte neutrolization in io.netty:netty-codec-socks
CVE-2026-XXXXX : SNI bypass in io.netty:netty-handler
CVE-2026-59902 : memory exhaustion in io.netty:netty-transport-sctp
CVE-2026-59903 : cache poisoning & info disclosure in io.netty:netty-codec-http
CVE-2026-XXXXX : validation bypass in io.netty:netty-codec-mqtt
CVE-2026-XXXXX : improper hostname verification in io.netty:netty-handler
Other significant changes are:
AsciiString.cached(String) should sanitize the provided String #17007
Fix AsciiString.cached(String) performance regression #17074
SslHandler: Fix possible buffer leak when an OOME is thrown during allocation #17059
Add HttpContentCompressor constructor with ability to...
[Less]
|
|
Posted
about 1 month
ago
by
chrisvest
We are happy to announce the release of netty 4.1.136.Final. This is a bug-fix and security release.
We strongly recommend upgrading to this version to get the following security fixes:
CVE-2026-44891: memory exhaustion in
... [More]
io.netty:netty-codec-stomp.
CVE-2026-55833: zip bomb in io.netty:netty-codec-http.
CVE-2026-59921: improper CR/LF neutrolization in io.netty:netty-codec-http (multipart).
CVE-2026-59919: improper CR/LF neutrolization in io.netty:netty-codec-haproxy.
CVE-2026-55851: memory exhaustion in io.netty:netty-codec-haproxy.
CVE-2026-56745: memory exhaustion in io.netty:netty-codec-http.
CVE-2026-56817: insecure defaults in XML parsing in io.netty:netty-codec-xml.
CVE-2026-59899: memory exhaustion in io.netty:netty-codec-http.
CVE-2026-56818: memory leak in io.netty:netty-codec-redis.
CVE-2026-56819: memory leak in io.netty:netty-codec-http2.
CVE-2026-55831: resource exhaustion/DoS in io.netty:netty-codec-http.
CVE-2026-XXXXX: memory leak in io.netty:netty-codec-dns.
CVE-2026-59901: infinite loop in io.netty:netty-codec-compression (bzip2).
CVE-2026-59900: improper header neutralization in io.netty:netty-codec-http2.
CVE-2026-59898: protocol version confusion in io.netty:netty-codec-http (websocket).
CVE-2026-56746: improper...
[Less]
|
|
Posted
about 1 month
ago
by
chrisvest
We are happy to announce the release of netty 4.1.136.Final. This is a bug-fix and security release.
We strongly recommend upgrading to this version to get the following security fixes:
CVE-2026-XXXXX: memory exhaustion in
... [More]
io.netty:netty-codec-stomp.
CVE-2026-55833: zip bomb in io.netty:netty-codec-http.
CVE-2026-XXXXX: improper CR/LF neutrolization in io.netty:netty-codec-http (multipart).
CVE-2026-XXXXX: improper CR/LF neutrolization in io.netty:netty-codec-haproxy.
CVE-2026-55851: memory exhaustion in io.netty:netty-codec-haproxy.
CVE-2026-56745: memory exhaustion in io.netty:netty-codec-http.
CVE-2026-56817: insecure defaults in XML parsing in io.netty:netty-codec-xml.
CVE-2026-XXXXX: memory exhaustion in io.netty:netty-codec-http.
CVE-2026-56818: memory leak in io.netty:netty-codec-redis.
CVE-2026-56819: memory leak in io.netty:netty-codec-http2.
CVE-2026-55831: resource exhaustion/DoS in io.netty:netty-codec-http.
CVE-2026-XXXXX: memory leak in io.netty:netty-codec-dns.
CVE-2026-XXXXX: infinite loop in io.netty:netty-codec-compression (bzip2).
CVE-2026-XXXXX: improper header neutralization in io.netty:netty-codec-http2.
CVE-2026-XXXXX: protocol version confusion in io.netty:netty-codec-http (websocket).
CVE-2026-56746: improper...
[Less]
|
|
Posted
about 1 month
ago
by
chrisvest
We are happy to announce the release of netty 4.2.16.Final. This is a bug-fix and security release.
We strongly recommend upgrading to this version to get the following security fixes:
CVE-2026-44891: memory exhaustion in
... [More]
io.netty:netty-codec-stomp.
CVE-2026-55833: zip bomb in io.netty:netty-codec-http.
CVE-2026-59921: improper CR/LF neutrolization in io.netty:netty-codec-http (multipart).
CVE-2026-59919: improper CR/LF neutrolization in io.netty:netty-codec-haproxy.
CVE-2026-55851: memory exhaustion in io.netty:netty-codec-haproxy.
CVE-2026-56745: memory exhaustion in io.netty:netty-codec-http.
CVE-2026-56817: insecure defaults in XML parsing in io.netty:netty-codec-xml.
CVE-2026-59899: memory exhaustion in io.netty:netty-codec-http.
CVE-2026-56818: memory leak in io.netty:netty-codec-redis.
CVE-2026-56819: memory leak in io.netty:netty-codec-http2.
CVE-2026-56816: memory exhaustion in io.netty:netty-codec-http3.
CVE-2026-55831: resource exhaustion/DoS in io.netty:netty-codec-http.
CVE-2026-XXXXX: memory leak in io.netty:netty-codec-dns.
CVE-2026-59901: infinite loop in io.netty:netty-codec-compression (bzip2).
CVE-2026-59900: improper header neutralization in io.netty:netty-codec-http2.
CVE-2026-59898: protocol version confusion...
[Less]
|
|
Posted
about 1 month
ago
by
chrisvest
We are happy to announce the release of netty 4.2.16.Final. This is a bug-fix and security release.
We strongly recommend upgrading to this version to get the following security fixes:
CVE-2026-XXXXX: memory exhaustion in
... [More]
io.netty:netty-codec-stomp.
CVE-2026-55833: zip bomb in io.netty:netty-codec-http.
CVE-2026-XXXXX: improper CR/LF neutrolization in io.netty:netty-codec-http (multipart).
CVE-2026-XXXXX: improper CR/LF neutrolization in io.netty:netty-codec-haproxy.
CVE-2026-55851: memory exhaustion in io.netty:netty-codec-haproxy.
CVE-2026-56745: memory exhaustion in io.netty:netty-codec-http.
CVE-2026-56817: insecure defaults in XML parsing in io.netty:netty-codec-xml.
CVE-2026-XXXXX: memory exhaustion in io.netty:netty-codec-http.
CVE-2026-56818: memory leak in io.netty:netty-codec-redis.
CVE-2026-56819: memory leak in io.netty:netty-codec-http2.
CVE-2026-56816: memory exhaustion in io.netty:netty-codec-http3.
CVE-2026-55831: resource exhaustion/DoS in io.netty:netty-codec-http.
CVE-2026-XXXXX: memory leak in io.netty:netty-codec-dns.
CVE-2026-XXXXX: infinite loop in io.netty:netty-codec-compression (bzip2).
CVE-2026-XXXXX: improper header neutralization in io.netty:netty-codec-http2.
CVE-2026-XXXXX: protocol version confusion...
[Less]
|
|
Posted
2 months
ago
by
chrisvest
We are happy to announce the release of netty 4.1.135.Final. This is a bug-fix and security release.
We strongly recommend upgrading to this version to get the following security fixes:
CVE-2026-48059: memory exhaustion in
... [More]
io.netty:netty-codec-haproxy (high).
CVE-2026-47691: DNS cache poisoning in io.netty:netty-resolver-dns (high).
CVE-2026-XXXXX: DDoS in io.netty:netty-codec-http2.
CVE-2026-50011: memory exhaustion in io.netty:netty-codec-redis (high).
CVE-2026-44250: memory exhaustion in io.netty:netty-codec-redis (high).
CVE-2026-44890: memory exhaustion in io.netty:netty-codec-redis (high).
CVE-2026-44249: IPv6 subnet filter bypass in io.netty:netty-handler (high).
CVE-2026-50020: request smuggling in io.netty:netty-codec-http.
CVE-2026-44893: memory leak in io.netty:netty-codec-haproxy (high).
CVE-2026-50010: TLS hostname verification accidentally disabled in io.netty:netty-handler (high).
CVE-2026-45673: DNS cache poisoning in io.netty:netty-resolver-dns.
CVE-2026-45416: excessive memory usage from SNIHandler in io.netty:netty-handler (high).
CVE-2026-45536: file descriptor leak in io.netty:netty-transport-native-epoll...
[Less]
|
|
Posted
2 months
ago
by
chrisvest
We are happy to announce the release of netty 4.1.135.Final. This is a bug-fix and security release.
We strongly recommend upgrading to this version to get the following security fixes:
CVE-2026-48059: memory exhaustion in
... [More]
io.netty:netty-codec-haproxy (high).
CVE-2026-47691: DNS cache poisoning in io.netty:netty-resolver-dns (high).
CVE-2026-50560: DDoS in io.netty:netty-codec-http2.
CVE-2026-50011: memory exhaustion in io.netty:netty-codec-redis (high).
CVE-2026-44250: memory exhaustion in io.netty:netty-codec-redis (high).
CVE-2026-44890: memory exhaustion in io.netty:netty-codec-redis (high).
CVE-2026-44249: IPv6 subnet filter bypass in io.netty:netty-handler (high).
CVE-2026-50020: request smuggling in io.netty:netty-codec-http.
CVE-2026-44893: memory leak in io.netty:netty-codec-haproxy (high).
CVE-2026-50010: TLS hostname verification accidentally disabled in io.netty:netty-handler (high).
CVE-2026-45673: DNS cache poisoning in io.netty:netty-resolver-dns.
CVE-2026-45416: excessive memory usage from SNIHandler in io.netty:netty-handler (high).
CVE-2026-45536: file descriptor leak in io.netty:netty-transport-native-epoll...
[Less]
|
|
Posted
2 months
ago
by
chrisvest
We are happy to announce the release of netty 4.1.135.Final. This is a bug-fix and security release.
We strongly recommend upgrading to this version to get the following security fixes:
CVE-2026-48059: memory exhaustion in
... [More]
io.netty:netty-codec-haproxy (high).
CVE-2026-47691: DNS cache poisoning in io.netty:netty-resolver-dns (high).
CVE-2026-XXXXX: DDoS in io.netty:netty-codec-http2.
CVE-2026-XXXXX: memory exhaustion in io.netty:netty-codec-redis (high).
CVE-2026-44250: memory exhaustion in io.netty:netty-codec-redis (high).
CVE-2026-44890: memory exhaustion in io.netty:netty-codec-redis (high).
CVE-2026-44249: IPv6 subnet filter bypass in io.netty:netty-handler (high).
CVE-2026-XXXXX: request smuggling in io.netty:netty-codec-http.
CVE-2026-44893: memory leak in io.netty:netty-codec-haproxy (high).
CVE-2026-XXXXX: TLS hostname verification accidentally disabled in io.netty:netty-handler (high).
CVE-2026-45673: DNS cache poisoning in io.netty:netty-resolver-dns.
CVE-2026-45416: excessive memory usage from SNIHandler in io.netty:netty-handler (high).
CVE-2026-45536: file descriptor leak in io.netty:netty-transport-native-epoll...
[Less]
|