11 Total advisories
11 Vulnerabilities
0 Malware
Dependency scanning
Check whether io.netty:netty is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 6.2
CVE-2021-21290
Local Information Disclosure Vulnerability in Netty on Unix-Like systems
MEDIUM 5.9
CVE-2021-21409
Possible request smuggling in HTTP/2 due missing validation of content-length
MEDIUM 6.5
CVE-2021-43797
HTTP request smuggling in netty
HIGH 7.5
CVE-2015-2156
Information Exposure in Netty
MEDIUM 5.9
CVE-2021-21295
Possible request smuggling in HTTP/2 due missing validation
HIGH 7.5
CVE-2021-37136
Bzip2Decoder doesn't allow setting size restrictions for decompressed data
HIGH 7.5
CVE-2021-37137
SnappyFrameDecoder doesn't restrict chunk length any may buffer skippable chunks in an unnecessary way
HIGH 7.5
CVE-2019-16869
HTTP Request Smuggling in Netty
CRITICAL 9.1
CVE-2019-20444
HTTP Request Smuggling in Netty
UNKNOWN
CVE-2014-0193
Netty denial of service vulnerability
UNKNOWN
CVE-2019-20445
HTTP Request Smuggling in Netty
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes