Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Netty

First CVE: May 6, 2014Active for: 12 yearsTotal CVEs: 72
69.7
VTI Score
TOP TARGET

Netty is a widely embedded, asynchronous networking library that underpins Java-based web servers, application frameworks, and messaging systems across enterprise and cloud infrastructure, making its vulnerability footprint disproportionately significant despite a narrow product roster. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the memory and protocol-handling demands of a low-level network I/O foundation. The exposure recurs through the core Netty library and its codec extensions, clustering around resource-consumption exhaustion, HTTP request/response smuggling and interpretation inconsistencies, improper input validation, and information disclosure—classes that arise naturally from parsing and state-management in a request-driven architecture. Because Netty sits deep in the Java supply chain, flaws propagate to every downstream application that bundles the library, amplifying the remediation burden for defenders tracking this vendor's advisories. Live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
72
Total CVEs
More Total CVEs than 99% of tracked vendors
3.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 52% of tracked vendors
1.4%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Netty over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 6, 2014
12 years ago
Most Recent CVE
Jul 21, 2026
4 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (72 CVEs).

72 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-44487HIGH
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through
Oct 10, 20237.597YESYES
CVE-2026-47691CRITICAL
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's `DnsResolveContext` insufficient
Jun 12, 202610.042NONO
CVE-2026-45674CRITICAL
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to valid
Jun 12, 202610.042NONO
CVE-2026-42581CRITICAL
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a r
May 13, 20269.839NONO
CVE-2026-42584CRITICAL
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request
May 13, 20269.138NONO
CVE-2026-42579CRITICAL
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints d
May 13, 20269.138NONO
CVE-2026-44249HIGH
Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass
Jun 11, 20268.137NONO
CVE-2026-50010HIGH
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SimpleTrustManagerFactory.engineGetTrust
Jun 12, 20267.535NONO
CVE-2026-45416HIGH
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SslClientHelloHandler.decode() reads the
Jun 12, 20267.535NONO
CVE-2026-48040CRITICAL
The netty incubator codec.bhttp is a java language binary http parser. The library implements Oblivious HTTP (RFC 9458) using BoringSSL's HPKE C library via JNI. When deriving nati
Jun 4, 20269.135NONO
View all 72 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products72 CVEs
31%
57%
13%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local6 (8.3%)
Network64 (88.9%)
Unknown2 (2.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low64 (88.9%)
High6 (8.3%)
Unknown2 (2.8%)
User Interaction
None69 (95.8%)
Unknown2 (2.8%)
Required1 (1.4%)
Privileges Required
Low6 (8.3%)
High0 (0.0%)
None64 (88.9%)
Unknown2 (2.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (72 CVEs).

CISA KEV
1 CVE
1.4% of CVEs· 99th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
1.4% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Netty.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Netty — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Netty's Products

View all 4 CNAs →

Top CWEs