Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:maven/io.netty/netty-codec-http

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Netty's HttpServerCodec in versions 4.2.0.Final through 4.2.16.Final and up to 4.1.136.Final contains a vulnerability where HTTP response parsing can become desynchronized. This occurs when a client sends a pipelined HTTP/1.1 GET request with an Expect: 100-continue header followed by a HEAD request. The 100 Continue response consumes the queued GET method incorrectly, causing the GET response body to be dropped and the HEAD response body to be misinterpreted as the GET body. This leads to response splitting and unsafe connection reuse. The issue is fixed in versions 4.2.17.Final and 4.1.137.Final.

Join the discussion

Netty's io.netty:netty-codec-http component contains an unbounded per-connection queue in WebSocketServerExtensionHandler. This queue grows without limit when a remote unauthenticated attacker sends HTTP/1.1 pipelined requests faster than the server responds, potentially causing the JVM to run out of heap memory and crash. The vulnerability affects versions 4.1.88.Final through 4.1.137.Final and 4.2.0.Final through 4.2.17.Final. It is fixed in versions 4.1.138.Final and 4.2.18.Final.

Join the discussion

Netty's HttpServerCodec component has a vulnerability where an unbounded queue can grow per connection due to pipelined HTTP/1.1 requests. This flaw allows a remote attacker to cause unbounded heap growth and denial of service by withholding reads, preventing responses from being flushed. The issue affects versions 4.2.0.Final through 4.2.17.Final and all releases up to and including 4.1.137.Final. It is fixed in versions 4.2.18.Final and 4.1.138.Final.

Join the discussion

Netty's io.netty:netty-codec-http library versions up to 4.1.137.Final and from 4.2.0.Final through 4.2.17.Final have a vulnerability where the SpdySessionHandler accepts an unlimited number of concurrent SPDY streams. This can lead to unbounded memory allocation when a remote peer sends many SYN_STREAM frames, causing a JVM OutOfMemoryError and service crash. The issue is fixed in versions 4.1.138.Final and 4.2.18.Final.

Join the discussion

Netty versions 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final contain a vulnerability in the validation of the final transfer coding in the Transfer-Encoding header. This flaw allows attackers to craft malformed encoding declarations to bypass validation and perform HTTP request smuggling attacks by splitting or manipulating Transfer-Encoding headers.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Package: pkg:maven/io.netty/netty-codec-http
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses