pkg:Maven/io.netty:netty-codec-http
15 total CVEsCRITICAL1HIGH4MEDIUM10
✅ Check your installed version
All known vulnerabilities
- from 0, < 4.1.44
- HIGH7.5CVE-2026-42587Netty: HttpContentDecompressor maxAllocation bypass when Content-Encoding set to br/zstd/snappy leads to decompression bomb DoS>= 4.2.0.Alpha1, < 4.2.13.Final
- from 0, < 4.1.132.Final
- HIGH7.5CVE-2025-58056Netty vulnerable to request smuggling due to incorrect parsing of chunk extensionsfrom 0, < 4.1.125.Final
- >= 4.2.0.Alpha1, < 4.2.13.Final
- MEDIUM6.5CVE-2026-42585Netty vulnerable to HTTP Request Smuggling due to malformed Transfer-Encoding>= 4.2.0.Alpha1, < 4.2.13.Final
- MEDIUM6.5CVE-2026-42580Netty vulnerable to HTTP Request Smuggling due to incorrect chunk size parsing>= 4.2.0.Alpha1, < 4.2.13.Final
- MEDIUM6.5CVE-2025-67735Netty has a CRLF Injection vulnerability in io.netty.handler.codec.http.HttpRequestEncoder>= 4.2.0.Alpha1, < 4.2.8.Final
- MEDIUM6.5CVE-2022-41915Netty vulnerable to HTTP Response splitting from assigning header value iterator>= 4.1.83.Final, < 4.1.86.Final
- >= 4.0.0, < 4.1.71.Final
- >= 4.0.0, < 4.1.59.Final
- >= 4.2.0.Alpha1, < 4.2.13.Final
- from 0, < 4.1.77.Final
- MEDIUM5.3CVE-2026-41417Netty: Start-Line Injection in DefaultHttpRequest.setUri() Allows HTTP Request Smuggling and RTSP Request Injectionfrom 0, < 4.1.133.Final
- from 0, < 4.1.108.Final