11 Total advisories
11 Vulnerabilities
0 Malware
Dependency scanning
Check whether io.netty:netty-codec-http2 is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 5.3
CVE-2026-48043
netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion
UNKNOWN
CVE-2026-59900
Netty: [codec-http2] Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass
HIGH 7.5
CVE-2026-56819
Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)
HIGH 7.5
CVE-2026-42587
Netty: HttpContentDecompressor maxAllocation bypass when Content-Encoding set to br/zstd/snappy leads to decompression bomb DoS
MEDIUM 5.3
CVE-2026-47244
Netty HTTP/2: Advertised MAX_CONCURRENT_STREAMS are not enforced
MEDIUM 5.3
CVE-2026-50560
Netty susceptible to HTTP/2 Reset Attack with different on-the-wire signature
UNKNOWN
CVE-2026-33871
Netty HTTP/2 CONTINUATION Frame Flood DoS via Zero-Byte Frame Bypass
HIGH 7.5
CVE-2025-55163
Netty affected by MadeYouReset HTTP/2 DDoS vulnerability
HIGH 7.5
GHSA-xpw8-rcwv-8f8p
io.netty:netty-codec-http2 vulnerable to HTTP/2 Rapid Reset Attack
MEDIUM 5.9
CVE-2021-21409
Possible request smuggling in HTTP/2 due missing validation of content-length
MEDIUM 5.9
CVE-2021-21295
Possible request smuggling in HTTP/2 due missing validation
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes