13 Total advisories
13 Vulnerabilities
0 Malware
Dependency scanning
Check whether io.netty:netty-handler is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.5
CVE-2026-50010
Netty: Wrapping plain trust manager silently disables hostname verification
HIGH 8.1
CVE-2026-44249
Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking
HIGH 7.5
CVE-2025-24970
SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine
HIGH 7.5
CVE-2026-45416
Netty: SNI handler pre-allocates up to 16 MiB from nine attacker bytes
MEDIUM 5.3
CVE-2023-4586
Withdrawn Advisory: Netty-handler does not validate host names by default
MEDIUM 6.5
CVE-2023-34462
netty-handler SniHandler 16MB allocation
UNKNOWN
CVE-2026-75595
Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext
UNKNOWN
CVE-2026-75596
Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing
HIGH 7.5
CVE-2020-7238
HTTP Request Smuggling in Netty
HIGH 7.5
CVE-2020-11612
Denial of Service in Netty
HIGH 7.5
CVE-2016-4970
Loop with Unreachable Exit Condition in Netty
UNKNOWN
CVE-2019-20445
HTTP Request Smuggling in Netty
UNKNOWN
CVE-2014-3488
Denial of service in Netty
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes