netty security advisories
3 threat alerts tracking vulnerabilities and security advisories that affect netty products.
Vulnios monitors netty CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent netty security news in one place, or click into an individual alert for full detail.
Critical Vulnerability: CVE-2019-20445 — netty, debian — netty, debian_linux
HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.
criticalCVE-2019-20445Critical Vulnerability: CVE-2019-20444 — netty, debian — netty, debian_linux
HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an "invalid
criticalCVE-2019-20444Critical Vulnerability: CVE-2026-48040 — netty — netty-incubator-codec-ohttp
The netty incubator codec.bhttp is a java language binary http parser. The library implements Oblivious HTTP (RFC 9458) using BoringSSL's HPKE C library via JNI. When deriving native memory addresses
criticalCVE-2026-48040
Track netty exposure across your environment
Vulnios automatically cross-references your asset inventory against new netty CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan