FLAT-0KTOS (GHSA-v74w-7mr3-4qg3)
Asymmetric denial of service - ReDoS In io.netty:netty-codec-xml
7.7
High
Ecosystem: Maven
Component: io.netty:netty-codec-xml
FLAT-OXWXB (GHSA-mfg7-5gfp-c4w3)
Improper resource allocation In io.netty:netty-codec-dns
7.7
High
Ecosystem: Maven
Component: io.netty:netty-codec-dns
FLAT-WCCUA (CVE-2026-59921)
Lack of data validation In io.netty:netty-codec-http
5.9
Medium
Ecosystem: Maven
Component: io.netty:netty-codec-http
FLAT-W5XFN (CVE-2026-59920)
Lack of data validation In io.netty:netty-codec-stomp
6.3
Medium
Ecosystem: Maven
Component: io.netty:netty-codec-stomp
FLAT-MABVG (CVE-2026-59919)
Lack of data validation In io.netty:netty-codec-haproxy
3.3
Low
Ecosystem: Maven
Component: io.netty:netty-codec-haproxy
FLAT-DR0H9 (CVE-2026-59901)
Improper resource allocation In io.netty:netty-codec-compression
6.6
Medium
Ecosystem: Maven
Component: io.netty:netty-codec-compression
FLAT-S5QFY (CVE-2026-59900)
HTTP request smuggling In io.netty:netty-codec-http2
2.7
Low
Ecosystem: Maven
Component: io.netty:netty-codec-http2
FLAT-FJZVA (CVE-2026-59899)
Improper resource allocation In io.netty:netty-codec-http
2.7
Low
Ecosystem: Maven
Component: io.netty:netty-codec-http
FLAT-UA50D (CVE-2026-59898)
HTTP request smuggling In io.netty:netty-codec-http
1.7
Low
Ecosystem: Maven
Component: io.netty:netty-codec-http
FLAT-1TSUI (CVE-2026-56822)
Race condition In io.netty:netty-handler-ssl-ocsp
8.1
High
Ecosystem: Maven
Component: io.netty:netty-handler-ssl-ocsp
FLAT-7F5XJ (CVE-2026-56821)
Insecure service configuration - Certificates In io.netty:netty-handler-ssl-ocsp
8.1
High
Ecosystem: Maven
Component: io.netty:netty-handler-ssl-ocsp
FLAT-7GUKW (CVE-2026-56820)
Insecure digital certificates In io.netty:netty-handler-ssl-ocsp
8.1
High
Ecosystem: Maven
Component: io.netty:netty-handler-ssl-ocsp
FLAT-DG3PO (CVE-2026-56817)
XML injection (XXE) In io.netty:netty-codec-xml
4.8
Medium
Ecosystem: Maven
Component: io.netty:netty-codec-xml
FLAT-ZKBZA (CVE-2026-56816)
Improper resource allocation In io.netty:netty-codec-http3
7.7
High
Ecosystem: Maven
Component: io.netty:netty-codec-http3
FLAT-C9TEN (CVE-2026-56746)
Improper authorization control for web services In io.netty:netty-codec-http
7.9
High
Ecosystem: Maven
Component: io.netty:netty-codec-http
FLAT-ET9V4 (CVE-2026-56745)
Improper resource allocation In io.netty:netty-codec-http
6.6
Medium
Ecosystem: Maven
Component: io.netty:netty-codec-http
FLAT-1S899 (CVE-2026-55851)
Asymmetric denial of service - ReDoS In io.netty:netty-codec-haproxy
6.6
Medium
Ecosystem: Maven
Component: io.netty:netty-codec-haproxy
FLAT-5MVIT (CVE-2026-55833)
Improper resource allocation In io.netty:netty-codec-http
5.7
Medium
Ecosystem: Maven
Component: io.netty:netty-codec-http
FLAT-WLOAQ (CVE-2026-55831)
Asymmetric denial of service In io.netty:netty-codec-http
7.7
High
Ecosystem: Maven
Component: io.netty:netty-codec-http
FLAT-O6IRE (CVE-2026-56819)
Improper resource allocation In netty
6.3
Medium
Ecosystem: Debian
Component: netty
FLAT-FS0S5 (CVE-2026-44891)
Improper resource allocation In netty
7.7
High
Ecosystem: Debian
Component: netty
FLAT-RW8HR (CVE-2026-48480)
Insecure encryption algorithm In io.netty.incubator:netty-incubator-codec-ohttp
6.6
Medium
Ecosystem: Maven
Component: io.netty.incubator:netty-incubator-codec-ohttp
FLAT-QGBTP (CVE-2026-50560)
Asymmetric denial of service In io.netty:netty-codec-http2
2.7
Low
Ecosystem: Maven
Component: io.netty:netty-codec-http2
FLAT-K37RJ (CVE-2026-50020)
HTTP request smuggling In io.netty:netty-codec-http
1.7
Low
Ecosystem: Maven
Component: io.netty:netty-codec-http
FLAT-J0BM8 (CVE-2026-50011)
Improper resource allocation In io.netty:netty-codec-redis
7.7
High
Ecosystem: Maven
Component: io.netty:netty-codec-redis
FLAT-455VT (CVE-2026-50010)
Insecure digital certificates In io.netty:netty-handler
8.1
High
Ecosystem: Maven
Component: io.netty:netty-handler
FLAT-9QUEH (CVE-2026-50009)
Use of insecure channel - Source code In io.netty:netty-codec-classes-quic
1.7
Low
Ecosystem: Maven
Component: io.netty:netty-codec-classes-quic
FLAT-QWT22 (CVE-2026-48748)
Improper resource allocation In io.netty:netty-codec-http3
7.7
High
Ecosystem: Maven
Component: io.netty:netty-codec-http3
FLAT-CK1S2 (CVE-2026-48043)
Improper resource allocation In netty
7.7
High
Ecosystem: Debian
Component: netty
FLAT-Z55UO (CVE-2026-48006)
Improper resource allocation In netty
6.6
Medium
Ecosystem: Debian
Component: netty
FLAT-JXVT2 (CVE-2026-48059)
Improper resource allocation In netty
6.6
Medium
Ecosystem: Debian
Component: netty
FLAT-BE9J6 (CVE-2026-47691)
Insufficient data authenticity validation In netty
8.1
High
Ecosystem: Debian
Component: netty
FLAT-K5Z73 (CVE-2026-47244)
Improper resource allocation In netty
6.3
Medium
Ecosystem: Debian
Component: netty
FLAT-B6XK0 (CVE-2026-45536)
Improper resource allocation In netty
1.0
Low
Ecosystem: Debian
Component: netty
FLAT-FYYZE (CVE-2026-45674)
Insufficient data authenticity validation In netty
8.2
High
Ecosystem: Debian
Component: netty
FLAT-0W80F (CVE-2026-46340)
Inadequate file size control In netty
7.7
High
Ecosystem: Debian
Component: netty
FLAT-B1QKT (CVE-2026-45673)
Insecure generation of random numbers In netty
6.6
Medium
Ecosystem: Debian
Component: netty
FLAT-JAL2X (CVE-2026-45416)
Improper resource allocation In netty
7.7
High
Ecosystem: Debian
Component: netty
FLAT-IUF0F (CVE-2026-44894)
Use of insecure channel - Source code In netty
6.5
Medium
Ecosystem: Debian
Component: netty
FLAT-XRS44 (CVE-2026-44893)
Improper control of interaction frequency In netty
7.7
High
Ecosystem: Debian
Component: netty
FLAT-9ZLJW (CVE-2026-44892)
Improper resource allocation In netty
7.7
High
Ecosystem: Debian
Component: netty
FLAT-K0FYF (CVE-2026-44250)
Asymmetric denial of service - ReDoS In netty
7.7
High
Ecosystem: Debian
Component: netty
FLAT-F5C86 (CVE-2026-44890)
Asymmetric denial of service - ReDoS In netty
6.3
Medium
Ecosystem: Debian
Component: netty
FLAT-VFKDA (CVE-2026-44249)
Improper authorization control for web services In netty
8.9
High
Ecosystem: Debian
Component: netty
FLAT-A3P4E (CVE-2026-48040)
Out-of-bounds read In io.netty.incubator:netty-incubator-codec-ohttp-hpke-native-boringssl
6.8
Medium
Ecosystem: Maven
Component: io.netty.incubator:netty-incubator-codec-ohttp-hpke-native-boringssl
FLAT-JNNU0 (CVE-2026-41207)
Insecure generation of random numbers In io.netty.incubator:netty-incubator-codec-ohttp
2.7
Low
Ecosystem: Maven
Component: io.netty.incubator:netty-incubator-codec-ohttp
FLAT-48R9Q (CVE-2026-44248)
Improper resource allocation In netty
7.7
High
Ecosystem: Debian
Component: netty
FLAT-JJ93J (CVE-2026-42586)
Lack of data validation In netty
8.1
High
Ecosystem: Debian
Component: netty
FLAT-WT2GQ (CVE-2026-42585)
HTTP request smuggling In netty
1.7
Low
Ecosystem: Debian
Component: netty
FLAT-VFAE9 (CVE-2026-42584)
HTTP request smuggling In netty
1.7
Low
Ecosystem: Debian
Component: netty
FLAT-MIVC1 (CVE-2026-42587)
Improper resource allocation In netty
6.3
Medium
Ecosystem: Debian
Component: netty
FLAT-RU9B2 (CVE-2026-42577)
Improper resource allocation In netty
6.3
Medium
Ecosystem: Debian
Component: netty
FLAT-D81AU (CVE-2026-42582)
Improper resource allocation In netty
7.7
High
Ecosystem: Debian
Component: netty
FLAT-30PNB (CVE-2026-42580)
HTTP request smuggling In netty
2.7
Low
Ecosystem: Debian
Component: netty
FLAT-APFOK (CVE-2026-42578)
Lack of data validation In netty
1.7
Low
Ecosystem: Debian
Component: netty
FLAT-5XY9B (CVE-2026-42581)
HTTP request smuggling In netty
1.7
Low
Ecosystem: Debian
Component: netty
FLAT-3H94N (CVE-2026-42579)
Asymmetric denial of service - ReDoS In netty
8.3
High
Ecosystem: Debian
Component: netty
FLAT-PZTU9 (CVE-2026-42583)
Improper resource allocation In netty
7.7
High
Ecosystem: Debian
Component: netty
FLAT-Q5I01 (CVE-2026-41417)
HTTP request smuggling In netty
2.5
Low
Ecosystem: Debian
Component: netty
FLAT-SO19H (DLA-4519-1)
Insecure HTTP methods enabled In netty
1.3
Low
Ecosystem: Debian
Component: netty
FLAT-4F9RE (CVE-2026-33870)
HTTP request smuggling In netty
7.8
High
Ecosystem: Debian
Component: netty
FLAT-VPPO3 (CVE-2026-33871)
Inadequate file size control In netty
6.6
Medium
Ecosystem: Debian
Component: netty
FLAT-XSGOF (DSA-6160-1)
Insecure HTTP methods enabled In netty
1.3
Low
Ecosystem: Debian
Component: netty
FLAT-AFBEE (CVE-2025-67735)
Lack of data validation In netty
1.7
Low
Ecosystem: Debian
Component: netty
FLAT-WO9GS (CVE-2025-59419)
OS Command Injection In io.netty:netty-codec-smtp
6.6
Medium
Ecosystem: Maven
Component: io.netty:netty-codec-smtp
FLAT-9FECW (CVE-2025-58056)
HTTP request smuggling In io.netty:netty-codec-http
2.7
Low
Ecosystem: Maven
Component: io.netty:netty-codec-http
FLAT-IU3XU (CVE-2025-58057)
Improper resource allocation In netty
2.7
Low
Ecosystem: Debian
Component: netty
FLAT-SC4SO (MAL-2025-35856)
Use of software with malware In test-mlw2-netty-thews
5.2
Medium
Ecosystem: Npm
Component: test-mlw2-netty-thews
FLAT-GIU74 (CVE-2025-55163)
Asymmetric denial of service In io.grpc:grpc-netty-shaded
4.6
Medium
Ecosystem: Maven
Component: io.grpc:grpc-netty-shaded
FLAT-L4SZG (CVE-2025-22227)
Sensitive information sent insecurely In io.projectreactor.netty:reactor-netty-http
0.6
Low
Ecosystem: Maven
Component: io.projectreactor.netty:reactor-netty-http
FLAT-4LWNI (CVE-2025-29908)
Improper resource allocation In io.netty.incubator:netty-incubator-codec-quic
2.7
Low
Ecosystem: Maven
Component: io.netty.incubator:netty-incubator-codec-quic
FLAT-5JX8H (CVE-2025-25193)
Improper resource allocation In io.netty:netty-common
4.3
Medium
Ecosystem: Maven
Component: io.netty:netty-common
FLAT-QARR6 (CVE-2025-24970)
Lack of data validation In io.netty:netty-handler
6.6
Medium
Ecosystem: Maven
Component: io.netty:netty-handler
FLAT-V8B11 (CVE-2024-47535)
Improper resource allocation In io.netty:netty-common
4.3
Medium
Ecosystem: Maven
Component: io.netty:netty-common
FLAT-P88C5 (CVE-2024-9622)
HTTP request smuggling In org.jboss.resteasy:resteasy-netty4-cdi
2.7
Low
Ecosystem: Maven
Component: org.jboss.resteasy:resteasy-netty4-cdi
FLAT-MU88L (CVE-2024-40642)
Lack of data validation In io.netty.incubator:netty-incubator-codec-bhttp
8.4
High
Ecosystem: Maven
Component: io.netty.incubator:netty-incubator-codec-bhttp
FLAT-VFQ6T (DLA-3834-1)
Lack of data validation In netty
1.3
Low
Ecosystem: Debian
Component: netty
FLAT-MPTY5 (CVE-2024-36121)
Out-of-bounds read In io.netty.incubator:netty-incubator-codec-ohttp
4.8
Medium
Ecosystem: Maven
Component: io.netty.incubator:netty-incubator-codec-ohttp
FLAT-VN4SM (CVE-2024-29025)
Improper resource allocation In netty
2.7
Low
Ecosystem: Debian
Component: netty
FLAT-N82H1 (CVE-2024-23639)
Remote command execution In io.micronaut:micronaut-http-server-netty
0.5
Low
Ecosystem: Maven
Component: io.micronaut:micronaut-http-server-netty
FLAT-4HBJL (CVE-2023-34054)
Asymmetric denial of service In io.projectreactor.netty:reactor-netty-core
6.6
Medium
Ecosystem: Maven
Component: io.projectreactor.netty:reactor-netty-core
FLAT-RWU5V (DLA-3656-1)
Improper authorization control for web services In netty
2.7
Low
Ecosystem: Debian
Component: netty
FLAT-Y3RZG (DSA-5558-1)
Lack of data validation In netty
1.3
Low
Ecosystem: Debian
Component: netty
FLAT-8EDR5 (CVE-2023-34062)
Lack of data validation - Path Traversal In io.projectreactor.netty:reactor-netty-http
6.6
Medium
Ecosystem: Maven
Component: io.projectreactor.netty:reactor-netty-http
FLAT-H84BT (GHSA-xpw8-rcwv-8f8p)
Asymmetric denial of service In io.netty:netty-codec-http2
6.6
Medium
Ecosystem: Maven
Component: io.netty:netty-codec-http2
FLAT-W1ORB (CVE-2023-4586)
Insecure digital certificates In io.netty:netty-handler
0.0
None
Ecosystem: Maven
Component: io.netty:netty-handler
FLAT-LC289 (CVE-2023-34462)
Improper resource allocation In netty
2.3
Low
Ecosystem: Debian
Component: netty
FLAT-ZSQ88 (DSA-5316-1)
Lack of data validation In netty
1.3
Low
Ecosystem: Debian
Component: netty
FLAT-TZ269 (DLA-3268-1)
Lack of data validation In netty
1.3
Low
Ecosystem: Debian
Component: netty
FLAT-AK4VI (CVE-2022-41915)
Lack of data validation In netty
2.7
Low
Ecosystem: Debian
Component: netty
FLAT-H1DE3 (CVE-2022-41881)
Improper resource allocation In io.netty:netty-codec-haproxy
4.9
Medium
Ecosystem: Maven
Component: io.netty:netty-codec-haproxy
FLAT-JOEZ2 (CVE-2022-31684)
Enabled default configuration In io.projectreactor.netty:reactor-netty-http
1.3
Low
Ecosystem: Maven
Component: io.projectreactor.netty:reactor-netty-http
FLAT-SFVND (CVE-2014-0193)
Asymmetric denial of service In io.netty:netty-all
6.6
Medium
Ecosystem: Maven
Component: io.netty:netty-all
FLAT-P6CC7 (CVE-2016-4970)
Inappropriate coding practices In io.netty:netty-handler
6.6
Medium
Ecosystem: Maven
Component: io.netty:netty-handler
FLAT-P77TR (CVE-2022-24823)
Insecure temporary files In io.netty:netty-codec-http
1.9
Low
Ecosystem: Maven
Component: io.netty:netty-codec-http
FLAT-H89G7 (CVE-2021-21290)
Insecure temporary files In io.netty:netty-codec-http2
0.0
None
Ecosystem: Maven
Component: io.netty:netty-codec-http2
FLAT-9C0WW (CVE-2020-5403)
Insecure deserialization In io.projectreactor.netty:reactor-netty-http
4.9
Medium
Ecosystem: Maven
Component: io.projectreactor.netty:reactor-netty-http
FLAT-9DZQR (CVE-2020-5404)
Weak credential policy In io.projectreactor.netty:reactor-netty-http
2.3
Low
Ecosystem: Maven
Component: io.projectreactor.netty:reactor-netty-http
FLAT-JF67S (CVE-2019-10797)
Lack of data validation In org.wso2.transport.http:org.wso2.transport.http.netty
4.9
Medium
Ecosystem: Maven
Component: org.wso2.transport.http:org.wso2.transport.http.netty
FLAT-L75X6 (CVE-2021-43797)
HTTP request smuggling In netty
4.9
Medium
Ecosystem: Debian
Component: netty