Official source evidencegithub.comVersioned article
Official source article · github.com

Release netty-4.2.16.Final · netty/netty · GitHub

BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.

Read the official article ↗
Publishergithub.com
Article IDNo stable ID in source URL
Verified snapshot27 Sept 2026, 20:00 UTC
Linked CVEs15

Linked CVE reports

These are source relationships, not a claim that this article fixes every affected product or branch.

  • CVE-2026-73507Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion
  • CVE-2026-73508Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names
  • CVE-2026-59898Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation
  • CVE-2026-59899Netty HttpContentEncoder: Unbounded Per-Connection Queue Growth via HTTP/1.1 Pipelining Leads to Denial of Service
  • CVE-2026-59900Netty codec-http2: Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass
  • CVE-2026-56820Netty: Missing CertificateID Validation in OCSP Response Allows Replay Attacks
  • CVE-2026-55831Netty SPDY SETTINGS frame count materializes unbounded settings map
  • CVE-2026-55851Netty codec-haproxy: Signed-Byte Sentinel Collision in HAProxyMessageDecoder Leads to Unbounded Memory Exhaustion
  • CVE-2026-56819Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)
  • CVE-2026-56816Netty: Memory Exhaustion via HTTP/3 Reserved Frame Types
  • CVE-2026-56817Netty: XML External Entity (XXE) injection via unconfigured XML factory when DTD and entity processing are enabled
  • CVE-2026-56745Netty SpdyHttpDecoder: ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustion
  • CVE-2026-56746Netty has a Security Control Bypass via CORS Short-Circuit Failure
  • CVE-2026-55833Netty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation
  • CVE-2026-44891Netty: Denial of Service via Unbounded Headers in StompSubframeDecoder

Source and provenance

Original title: Release netty-4.2.16.Final · netty/netty · GitHub. Captured 27 Sept 2026, 20:00 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.

Open the publisher's current version ↗