目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1325 CNY

100%

netty 产品漏洞列表 / CVE 中文分析 55

netty 产品相关 55 条漏洞,AI 中文标题与摘要、CVSS、POC 一站汇总。

本页是关于网络应用框架 Netty 的漏洞聚合信息,主要涵盖由厂商发布的各类安全缺陷与风险公告。收录内容聚焦于 Netty 框架在连接管理、协议处理及资源释放等环节存在的高危漏洞,时间范围覆盖该产品发布至今的历史安全事件。读者可借此追踪特定厂商的安全补丁动态,深入了解分布式系统中常见的远程代码执行与拒绝服务类弱点成因,并高效检索 Netty 相关产品的历史漏洞记录以评估自身系统风险。

ベンダー: netty

CVE IDタイトルCVSS深刻度公開日
CVE-2026-50560 Netty susceptible to HTTP/2 Reset Attack with different on-the-wire signature CWE-770--2026-06-12
CVE-2026-50020 Netty's HttpObjectDecoder skips arbitrary initial control characters when only initial CRLF characters are permitted CWE-444 5.3 Medium2026-06-12
CVE-2026-50011 Netty has unbounded pre-allocation in RedisArrayAggregator from RESP array length CWE-400 7.5 High2026-06-12
CVE-2026-50010 Netty's wrapping plain trust manager silently disables hostname verification CWE-347 7.5 High2026-06-12
CVE-2026-50009 Netty QUIC stateless reset token material exposed through header-visible connection IDs CWE-200 4.8 Medium2026-06-12
CVE-2026-48748 Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion CWE-770 7.5 High2026-06-12
CVE-2026-48059 Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion CWE-401--2026-06-12
CVE-2026-48043 netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion CWE-400 5.3 Medium2026-06-12
CVE-2026-48006 Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator CWE-401--2026-06-12
CVE-2026-47691 Netty has Insufficient Bailiwick Validation for NS Records CWE-345 8.7 High2026-06-12
CVE-2026-47244 Netty HTTP/2: Advertised MAX_CONCURRENT_STREAMS are not enforced CWE-400 5.3 Medium2026-06-12
CVE-2026-46340 Netty: SCTP reassembly nests buffers without bound CWE-770 7.5 High2026-06-12
CVE-2026-45674 Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records CWE-345 8.7 High2026-06-12
CVE-2026-45673 Netty: DNS Cache Poisoning due to Predictable PRNG and Default Static Source Port CWE-330 6.8 Medium2026-06-12
CVE-2026-45536 Netty: Unix-socket fd receive leaks descriptors when peer sends two at once CWE-200 4.0 Medium2026-06-12
CVE-2026-45416 Netty: SNI handler pre-allocates up to 16 MiB from nine attacker bytes CWE-770 7.5 High2026-06-12
CVE-2026-44894 Netty's Default QUIC token handler accepts any client-supplied token CWE-940 7.5 High2026-06-12
CVE-2026-44893 Netty: HAProxy SSL TLV parsing leaks retained slice on invalid TLV length CWE-703 7.5 High2026-06-12
CVE-2026-44892 Netty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header Size CWE-400 7.5 High2026-06-12
CVE-2026-44890 Netty has Unbounded Direct Memory Consumption in its RedisDecoder CWE-400 7.5 High2026-06-11
CVE-2026-44250 Netty: Memory Exhaustion in RedisArrayAggregator due to Deeply Nested Arrays CWE-400 7.5 High2026-06-11
CVE-2026-44249 Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking CWE-284 8.1 High2026-06-11
CVE-2026-44248 Netty: Resource exhaustion in MqttDecoder CWE-400 5.3 Medium2026-05-13
CVE-2026-42587 Netty: HttpContentDecompressor maxAllocation bypass via Content-Encoding: br/zstd/snappy enables decompression bomb DoS CWE-400 7.5 High2026-05-13
CVE-2026-42586 Netty: CRLF Injection in Netty Redis Codec Encoder CWE-93 6.8 Medium2026-05-13
CVE-2026-42585 Netty: HTTP Request Smuggling due to malformed Transfer-Encoding CWE-444 6.5 Medium2026-05-13
CVE-2026-42584 Netty: HttpClientCodec response desynchronization CWE-444 7.3 High2026-05-13
CVE-2026-42583 Netty: Lz4FrameDecoder resource exhaustion CWE-400 7.5 High2026-05-13
CVE-2026-42582 Netty: HTTP/3 QPACK literal unbounded allocation CWE-770 7.5 High2026-05-13
CVE-2026-42580 Netty: HTTP Request Smuggling due to incorrect chunk size parsing CWE-444 6.5 Medium2026-05-13

netty 产品累计公开 55 条 CVE 漏洞,本页提供按时间倒序的完整列表,包含 CVSS、CWE、AI 中文摘要与可获取的 POC 链接。