Netty
112 CVEs tracked. 1 of them are in CISA KEV.
This hub aggregates every CVE we track for Netty, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Netty CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 1 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 2 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 1 |
| 2025-09 | 2 |
| 2025-10 | 1 |
| 2025-11 | 0 |
| 2025-12 | 1 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 2 |
| 2026-04 | 0 |
| 2026-05 | 13 |
| 2026-06 | 22 |
| 2026-07 | 19 |
| 2026-08 | 10 |
| 2026-09 | 13 |
Severity
How the 112 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical4
- High68
- Medium39
- Low1
Latest CVEs
The 15 most recently published vulnerabilities affecting Netty.
- CVE-2026-100666Netty 4.2.0 through 4.2.17 Response Desynchronization via HttpServerCodec7.3
- CVE-2026-100665Netty 4.2.11 through 4.2.17 QUIC Hostname Verification Bypass7.5
- CVE-2026-100664Netty 4.2.2 through 4.2.15 HTTP/1 Host Header Authority Confusion7.5
- CVE-2026-100663Netty HTTP/1 CONNECT authority-form mistranslated to malformed HTTP/37.5
- CVE-2026-100661Netty HTTP/3 QPACK Prefixed Integer DoS via Unbounded Accumulation7.5
- CVE-2026-100662Netty HTTP/3 QPACK encoder-stream unbounded memory exhaustion DoS7.5
- CVE-2026-100660Netty before 4.2.18.Final QpackEncoder Unbounded Memory Retention7.5
- CVE-2026-100658Netty before 4.1.138.Final Denial of Service via WebSocketServerExtensionHandler5.3
- CVE-2026-100659Netty 4.2.0 through 4.2.18 HTTP/3 Request Routing Bypass6.5
- CVE-2026-100657Netty before 4.1.138.Final ByteBuf Leak in StompSubframeDecoder7.5
- CVE-2026-100656Netty HttpServerCodec Unbounded Queue Growth via HTTP/1.1 Pipelining7.5
- CVE-2026-100655Netty before 4.1.138.Final Denial of Service via SpdySessionHandler7.5
- CVE-2026-89044Netty 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final HTTP Request Smuggling via Transfer-Encoding6.5
- CVE-2026-76816Netty: MQTT Topic Name and Client ID Validation Bypass3.5
- CVE-2026-62380Netty before 4.2.16.Final SOCKS Proxy Null Byte Injection7.5
Product grouping is registry-driven, with AI assist and human review. How it works