Package impact
Maven / io.netty:netty-codec-http
| CVE | Severity | CVSS | Risk | Flags | OS | Vendor | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-42581 | critical | 9.8 | 9.8 | 15d ago | Netty HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization | |||
| CVE-2026-42584 | critical | 9.1 | 9.1 | 15d ago | Netty has HttpClientCodec response desynchronization | |||
| CVE-2026-42587 | high | 7.5 | 7.5 | 15d ago | Netty: HttpContentDecompressor maxAllocation bypass when Content-Encoding set to br/zstd/snappy leads to decompression bomb DoS | |||
| CVE-2026-42585 | high | 7.5 | 7.5 | 15d ago | Netty vulnerable to HTTP Request Smuggling due to malformed Transfer-Encoding |