Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.handler.ssl.SslClientHelloHandler#decode checks the wrong offset before reading the four-byte TLS… (CVE-2026-75595)
A vulnerability in Netty prior to versions 4.1.137.Final and 4.2.17.Final causes the SslClientHelloHandler#decode method to check the wrong offset when reading the TLS handshake header. This can lead to an IndexOutOfBoundsException and fallback to the default SslContext instead of the SNI-specific context. In configurations where mutual TLS authentication is enforced per SNI, this fallback can allow an unauthenticated attacker to bypass the mutual TLS requirement. The issue is fixed in versions 4.1.137.Final and 4.2.17.Final.
AI Analysis
Technical Summary
Netty versions before 4.1.137.Final and 4.2.17.Final contain a flaw in the io.netty.handler.ssl.SslClientHelloHandler#decode method where it incorrectly checks the offset before reading the four-byte TLS handshake header. This causes an IndexOutOfBoundsException when a ClientHello message's handshake header spans multiple records, triggering a fallback to the default SslContext rather than the SNI-specific context. If the deployment relies solely on per-SNI clientAuth=REQUIRE for mutual TLS enforcement, and the default SslContext uses clientAuth=NONE or OPTIONAL without additional certificate verification, an unauthenticated remote attacker can bypass mutual TLS protections. The vulnerability is resolved in versions 4.1.137.Final and 4.2.17.Final.
Potential Impact
An unauthenticated remote attacker can bypass mutual TLS authentication in affected Netty versions if the deployment relies exclusively on per-SNI clientAuth=REQUIRE and the default SslContext is configured with clientAuth=NONE or OPTIONAL. This allows unauthorized access to protected routes that should require client certificate authentication. The vulnerability does not affect deployments with additional application-layer certificate verification or different clientAuth configurations.
Mitigation Recommendations
This vulnerability is fixed in Netty versions 4.1.137.Final and 4.2.17.Final. Users should upgrade to these or later versions to remediate the issue. No additional mitigations are indicated by the vendor advisory.
Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.handler.ssl.SslClientHelloHandler#decode checks the wrong offset before reading the four-byte TLS… (CVE-2026-75595)
Description
A vulnerability in Netty prior to versions 4.1.137.Final and 4.2.17.Final causes the SslClientHelloHandler#decode method to check the wrong offset when reading the TLS handshake header. This can lead to an IndexOutOfBoundsException and fallback to the default SslContext instead of the SNI-specific context. In configurations where mutual TLS authentication is enforced per SNI, this fallback can allow an unauthenticated attacker to bypass the mutual TLS requirement. The issue is fixed in versions 4.1.137.Final and 4.2.17.Final.
CVSS v3.1
Score 9.1critical
Affected software
pkg:deb/ubuntu/netty?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/netty?arch=source&distro=esm-apps-legacy/xenialpkg:deb/ubuntu/netty?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/netty?arch=source&distro=esm-apps/focalpkg:deb/ubuntu/netty?arch=source&distro=esm-apps/jammypkg:deb/ubuntu/netty?arch=source&distro=esm-apps/noblepkg:deb/ubuntu/netty?arch=source&distro=esm-apps/resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Netty versions before 4.1.137.Final and 4.2.17.Final contain a flaw in the io.netty.handler.ssl.SslClientHelloHandler#decode method where it incorrectly checks the offset before reading the four-byte TLS handshake header. This causes an IndexOutOfBoundsException when a ClientHello message's handshake header spans multiple records, triggering a fallback to the default SslContext rather than the SNI-specific context. If the deployment relies solely on per-SNI clientAuth=REQUIRE for mutual TLS enforcement, and the default SslContext uses clientAuth=NONE or OPTIONAL without additional certificate verification, an unauthenticated remote attacker can bypass mutual TLS protections. The vulnerability is resolved in versions 4.1.137.Final and 4.2.17.Final.
Potential Impact
An unauthenticated remote attacker can bypass mutual TLS authentication in affected Netty versions if the deployment relies exclusively on per-SNI clientAuth=REQUIRE and the default SslContext is configured with clientAuth=NONE or OPTIONAL. This allows unauthorized access to protected routes that should require client certificate authentication. The vulnerability does not affect deployments with additional application-layer certificate verification or different clientAuth configurations.
Mitigation Recommendations
This vulnerability is fixed in Netty versions 4.1.137.Final and 4.2.17.Final. Users should upgrade to these or later versions to remediate the issue. No additional mitigations are indicated by the vendor advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-75595
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:Pro:14.04:LTS","Ubuntu:Pro:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:Pro:22.04:LTS","Ubuntu:Pro:24.04:LTS","Ubuntu:Pro:26.04:LTS"]
- Cvss Version
- 3.1
Threat ID: 6ab4be53f7a7c54106f0aa32
Added to database: 09/24/2026, 06:08:19 UTC
Last enriched: 09/24/2026, 06:45:53 UTC
Last updated: 09/24/2026, 06:45:53 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.