Netty is a widely embedded, asynchronous networking library that underpins Java-based web servers, application frameworks, and messaging systems across enterprise and cloud infrastructure, making its vulnerability footprint disproportionately significant despite a narrow product roster. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the memory and protocol-handling demands of a low-level network I/O foundation. The exposure recurs through the core Netty library and its codec extensions, clustering around resource-consumption exhaustion, HTTP request/response smuggling and interpretation inconsistencies, improper input validation, and information disclosure—classes that arise naturally from parsing and state-management in a request-driven architecture. Because Netty sits deep in the Java supply chain, flaws propagate to every downstream application that bundles the library, amplifying the remediation burden for defenders tracking this vendor's advisories. Live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Netty over time
Signals from CVEs in this vendor scope (72 CVEs).
72 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2026-47691CRITICAL Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's `DnsResolveContext` insufficient | Jun 12, 2026 | 10.0 | 42 | NO | NO |
CVE-2026-45674CRITICAL Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to valid | Jun 12, 2026 | 10.0 | 42 | NO | NO |
CVE-2026-42581CRITICAL Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a r | May 13, 2026 | 9.8 | 39 | NO | NO |
CVE-2026-42584CRITICAL Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request | May 13, 2026 | 9.1 | 38 | NO | NO |
CVE-2026-42579CRITICAL Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints d | May 13, 2026 | 9.1 | 38 | NO | NO |
CVE-2026-44249HIGH Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass | Jun 11, 2026 | 8.1 | 37 | NO | NO |
CVE-2026-50010HIGH Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SimpleTrustManagerFactory.engineGetTrust | Jun 12, 2026 | 7.5 | 35 | NO | NO |
CVE-2026-45416HIGH Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SslClientHelloHandler.decode() reads the | Jun 12, 2026 | 7.5 | 35 | NO | NO |
CVE-2026-48040CRITICAL The netty incubator codec.bhttp is a java language binary http parser. The library implements Oblivious HTTP (RFC 9458) using BoringSSL's HPKE C library via JNI. When deriving nati | Jun 4, 2026 | 9.1 | 35 | NO | NO |
Signals from CVEs in this vendor scope (72 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Netty.
Media articles that mention a CVE ID that affects a product developed by Netty — matched by CVE ID, not by vendor name.