CVE-2014-0193

EPSS 4.1%

netty-3.9 - security update

Published: 5/13/2022Modified: 3/9/2026

Description

`WebSocket08FrameDecoder` in Netty 3.6.x before 3.6.9, 3.7.x before 3.7.1, 3.8.x before 3.8.2, 3.9.x before 3.9.1, and 4.0.x before 4.0.19 allows remote attackers to cause a denial of service (memory consumption) via a `TextWebSocketFrame` followed by a long stream of `ContinuationWebSocketFrames`.

Affected packages (3)

References (18)