Vulnerabilidades em netty

79 resultados
Análise Vexday

O framework Netty acumula 60 CVEs catalogadas, com destaque para um volume expressivo de 38 entradas registradas nos últimos 90 dias, o que indica um período recente de descoberta ou catalogação acelerada de vulnerabilidades e merece acompanhamento próximo por equipes de segurança. A taxa de exploração ativa está abaixo da média geral do catálogo KEV, sem nenhuma CVE confirmada em uso por atores maliciosos no momento, e sem registros de severidade crítica ou provas de conceito públicas disponíveis. O tipo de falha mais recorrente é CWE-400 (consumo descontrolado de recursos), padrão associado a condições de negação de serviço que, embora frequentemente subestimado, pode impactar disponibilidade em ambientes de alta carga. A CVE mais relevante no cenário atual é CVE-2021-21295, com score EPSS de 0,1889, sugerindo probabilidade moderada de exploração e justificando priorização na aplicação de correções para instalações que ainda não foram atualizadas.

CVE-2024-40642HIGHAbsent Input Validation in BinaryHttpParser in the netty incubator codec.bhttp EPSS 0.7%CVE-2026-33870HIGHNetty: HTTP Request Smuggling via Chunked Extension Quoted-String ParsingEPSS 0.6%CVE-2026-48059HIGHNetty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory ExhaustionEPSS 0.6%CVE-2026-48043MEDIUMnetty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory ExhaustionEPSS 0.6%CVE-2026-44893HIGHNetty: HAProxy SSL TLV parsing leaks retained slice on invalid TLV lengthEPSS 0.6%CVE-2026-55851HIGHNetty codec-haproxy: Signed-Byte Sentinel Collision in HAProxyMessageDecoder Leads to Unbounded Memory ExhaustionEPSS 0.6%CVE-2026-56745HIGHNetty SpdyHttpDecoder: ByteBuf Reference Leak on RST_STREAM Leads to Native Memory ExhaustionEPSS 0.6%CVE-2026-42581MEDIUMNetty: HTTP/1.0 TE+CL Coexistence Bypasses Smuggling SanitizationEPSS 0.6%CVE-2025-58057MEDIUMNetty's BrotliDecoder is vulnerable to DoS via zip bomb style attackEPSS 0.6%CVE-2025-29908MEDIUMNetty QUIC hash collision DoS attackEPSS 0.5%CVE-2026-56816HIGHNetty: Memory Exhaustion via HTTP/3 Reserved Frame TypesEPSS 0.5%CVE-2026-48006HIGHNetty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregatorEPSS 0.5%CVE-2026-44248MEDIUMNetty: Resource exhaustion in MqttDecoderEPSS 0.5%CVE-2026-50010HIGHNetty's wrapping plain trust manager silently disables hostname verificationEPSS 0.5%CVE-2026-42582HIGHNetty: HTTP/3 QPACK literal unbounded allocationEPSS 0.4%CVE-2026-42583HIGHNetty: Lz4FrameDecoder resource exhaustionEPSS 0.4%CVE-2026-55831HIGHNetty SPDY SETTINGS frame count materializes unbounded settings mapEPSS 0.4%CVE-2026-44891HIGHNetty: Denial of Service via Unbounded Headers in StompSubframeDecoderEPSS 0.4%CVE-2026-55833HIGHNetty SPDY zlib header block continues decoded expansion after maxHeaderSize truncationEPSS 0.4%CVE-2026-42577HIGHNetty: epoll transport denial of service via RST on half-closed TCP connectionEPSS 0.4%