Dependency scanning
Check whether io.netty:netty-codec-http is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-59903
Netty Vulnerable to Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite
CVE-2026-55831
Netty SPDY SETTINGS frame count materializes unbounded settings map
CVE-2026-56746
Netty: Security Control Bypass via CORS Short-Circuit Failure
CVE-2026-59898
Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation
CVE-2026-42581
Netty HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization
CVE-2026-42580
Netty vulnerable to HTTP Request Smuggling due to incorrect chunk size parsing
CVE-2026-42587
Netty: HttpContentDecompressor maxAllocation bypass when Content-Encoding set to br/zstd/snappy leads to decompression bomb DoS
CVE-2026-42584
Netty has HttpClientCodec response desynchronization
CVE-2026-42585
Netty vulnerable to HTTP Request Smuggling due to malformed Transfer-Encoding
CVE-2026-59899
Netty: [HttpContentEncoder] Unbounded Per-Connection Queue Growth via HTTP/1.1 Pipelining Leads to Denial of Service
CVE-2026-55833
Netty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation
CVE-2026-59921
Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
CVE-2026-50020
Netty: HttpObjectDecoder skips arbitrary initial control characters when only initial CRLF characters are permitted
CVE-2026-41417
Netty: Start-Line Injection in DefaultHttpRequest.setUri() Allows HTTP Request Smuggling and RTSP Request Injection
CVE-2026-33870
Netty: HTTP Request Smuggling via Chunked Extension Quoted-String Parsing
CVE-2025-67735
Netty has a CRLF Injection vulnerability in io.netty.handler.codec.http.HttpRequestEncoder
CVE-2025-58056
Netty vulnerable to request smuggling due to incorrect parsing of chunk extensions
CVE-2026-56745
Netty: [SpdyHttpDecoder] ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustion
CVE-2024-29025
Netty's HttpPostRequestDecoder can OOM
CVE-2021-21290
Local Information Disclosure Vulnerability in Netty on Unix-Like systems
CVE-2021-43797
HTTP request smuggling in netty
CVE-2022-24823
Local Information Disclosure Vulnerability in io.netty:netty-codec-http
CVE-2022-41915
Netty vulnerable to HTTP Response splitting from assigning header value iterator
CVE-2019-20444
HTTP Request Smuggling in Netty
Browse more Maven advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes