5 Total advisories
5 Vulnerabilities
0 Malware
Dependency scanning
Check whether io.netty:netty-codec is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.5
CVE-2026-42583
Netty Lz4FrameDecoder is vulnerable to resource exhaustion
UNKNOWN
CVE-2025-58057
Netty's decoders vulnerable to DoS via zip bomb style attack
UNKNOWN
CVE-2026-59901
Netty: [Bzip2Decoder] Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang
HIGH 7.5
CVE-2021-37136
Bzip2Decoder doesn't allow setting size restrictions for decompressed data
HIGH 7.5
CVE-2021-37137
SnappyFrameDecoder doesn't restrict chunk length any may buffer skippable chunks in an unnecessary way
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes