BlackTreeCVE IntelligenceOfficial source evidencegithub.comVersioned article
Official source article · github.com
Release netty-4.2.16.Final · netty/netty · GitHub
BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.
Read the official article ↗Publishergithub.com
Article IDNo stable ID in source URL
Verified snapshot27 Sept 2026, 20:00 UTC
Linked CVEs15
Linked CVE reports
These are source relationships, not a claim that this article fixes every affected product or branch.
- CVE-2026-73507Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion
- CVE-2026-73508Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names
- CVE-2026-59898Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation
- CVE-2026-59899Netty HttpContentEncoder: Unbounded Per-Connection Queue Growth via HTTP/1.1 Pipelining Leads to Denial of Service
- CVE-2026-59900Netty codec-http2: Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass
- CVE-2026-56820Netty: Missing CertificateID Validation in OCSP Response Allows Replay Attacks
- CVE-2026-55831Netty SPDY SETTINGS frame count materializes unbounded settings map
- CVE-2026-55851Netty codec-haproxy: Signed-Byte Sentinel Collision in HAProxyMessageDecoder Leads to Unbounded Memory Exhaustion
- CVE-2026-56819Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)
- CVE-2026-56816Netty: Memory Exhaustion via HTTP/3 Reserved Frame Types
- CVE-2026-56817Netty: XML External Entity (XXE) injection via unconfigured XML factory when DTD and entity processing are enabled
- CVE-2026-56745Netty SpdyHttpDecoder: ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustion
- CVE-2026-56746Netty has a Security Control Bypass via CORS Short-Circuit Failure
- CVE-2026-55833Netty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation
- CVE-2026-44891Netty: Denial of Service via Unbounded Headers in StompSubframeDecoder
Source and provenance
Original title: Release netty-4.2.16.Final · netty/netty · GitHub. Captured 27 Sept 2026, 20:00 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.
Open the publisher's current version ↗