pkg:Debian/netty
共 52 筆 CVECRITICAL5HIGH24MEDIUM22
✅ 檢查你的版本
所有已知漏洞
- from 0, < 1:4.1.48-4+deb11u2
- from 0, < 1:4.1.33-1+deb10u4
- from 0, < 1:4.1.7-2+deb9u2
- from 0, < 1:4.1.45-1
- from 0, < 1:4.1.33-1+deb10u2
- from 0, < 1:3.2.6.Final-2+deb8u2
- from 0, < 1:4.1.45-1
- HIGH7.5CVE-2026-42587Netty: HttpContentDecompressor maxAllocation bypass when Content-Encoding set to br/zstd/snappy leads to decompression bomb DoSfrom 0
- from 0
- from 0
- from 0
- HIGH7.5CVE-2026-42578Netty has HTTP Header Injection via HttpProxyHandler Disabled Validation (Incomplete Fix CVE-2025-67735)from 0
- from 0
- from 0
- from 0
- HIGH7.5CVE-2025-58056Netty vulnerable to request smuggling due to incorrect parsing of chunk extensionsfrom 0, < 1:4.1.48-4+deb11u3
- from 0, < 1:4.1.48-4+deb11u3
- from 0, < 1:4.1.48-4+deb11u3
- from 0, < 1:4.1.48-7+deb12u2
- from 0, < 1:4.0.37-1
- HIGH7.5CVE-2021-37137SnappyFrameDecoder doesn't restrict chunk length any may buffer skippable chunks in an unnecessary wayfrom 0, < 1:4.1.48-4+deb11u1
- from 0, < 1:4.1.48-4+deb11u1
- from 0, < 1:4.1.33-1+deb10u3
- from 0, < 1:4.1.48-4+deb11u1
- from 0, < 1:4.0.31-1
- from 0, < 1:4.1.48-1
- from 0, < 1:4.1.45-1
- from 0, < 1:3.2.6.Final-2+deb8u1
- from 0, < 1:4.1.7-2+deb9u1
- from 0, < 1:4.1.33-2
- from 0
- from 0
- MEDIUM6.5CVE-2026-42585Netty vulnerable to HTTP Request Smuggling due to malformed Transfer-Encodingfrom 0
- MEDIUM6.5CVE-2026-42580Netty vulnerable to HTTP Request Smuggling due to incorrect chunk size parsingfrom 0
- MEDIUM6.5CVE-2025-67735Netty has a CRLF Injection vulnerability in io.netty.handler.codec.http.HttpRequestEncoderfrom 0, < 1:4.1.48-4+deb11u3
- from 0, < 1:4.1.48-4+deb11u2
- from 0, < 1:4.1.48-4+deb11u2
- MEDIUM6.5CVE-2022-41915Netty vulnerable to HTTP Response splitting from assigning header value iteratorfrom 0, < 1:4.1.48-4+deb11u1
- from 0, < 1:4.1.48-4+deb11u1
- from 0, < 1:4.1.48-2
- from 0, < 1:4.1.7-2+deb9u3
- MEDIUM5.9CVE-2021-21409Possible request smuggling in HTTP/2 due missing validation of content-lengthfrom 0, < 1:4.1.48-4
- from 0, < 1:4.1.48-3
- from 0
- from 0
- from 0
- MEDIUM5.3CVE-2026-41417Netty: Start-Line Injection in DefaultHttpRequest.setUri() Allows HTTP Request Smuggling and RTSP Request Injectionfrom 0
- from 0, < 1:4.1.33-1+deb10u5
- from 0, < 1:4.1.48-4+deb11u3
- from 0, < 1:4.1.48-4+deb11u3
- from 0, < 1:4.1.48-4+deb11u1
- from 0, < 1:4.1.48-4+deb11u3