Search CVE reports


Toggle filters

121 – 130 of 40097 results

Status is adjusted based on your filters.


CVE-2026-42586

Medium priority
Needs evaluation

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output...

1 affected package

netty

Package 20.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-42585

Medium priority
Needs evaluation

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed...

1 affected package

netty

Package 20.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-42584

Medium priority
Needs evaluation

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for...

1 affected package

netty

Package 20.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-42583

Medium priority
Needs evaluation

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only...

1 affected package

netty

Package 20.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-42582

Medium priority
Needs evaluation

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute...

1 affected package

netty

Package 20.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-42581

Medium priority
Needs evaluation

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and...

1 affected package

netty

Package 20.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-42580

Medium priority
Needs evaluation

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in...

1 affected package

netty

Package 20.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-42579

Medium priority
Needs evaluation

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a...

1 affected package

netty

Package 20.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-42578

Medium priority
Needs evaluation

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled....

1 affected package

netty

Package 20.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-42577

Medium priority
Needs evaluation

Netty is an asynchronous, event-driven network application framework. From 4.2.0.Final to 4.2.13.Final , Netty's epoll transport fails to detect and close TCP connections that receive a RST after being half-closed, leading to...

1 affected package

netty

Package 20.04 LTS
netty Needs evaluation
Show less packages