Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-50009

Опубликовано: 12 июн. 2026
Источник: nvd
CVSS3: 4.8
EPSS Низкий

Описание

Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final, Netty QUIC exposes the stateless reset token on the network path when using the default HMAC-based connection-ID and stateless-reset-token generators. The reset token for the server's current source connection ID can be derived from bytes that appear as the connection ID in QUIC headers after a source-CID rotation. An on-path attacker observing the headers can use the token to perform a Denial of Service by sending a spoofed Stateless Reset packet. Version 4.2.15.Final patches the issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:*
Версия от 4.2.0 (включая) до 4.2.15 (исключая)

EPSS

Процентиль: 10%
0.00204
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 4.8
ubuntu
около 2 месяцев назад

Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final, Netty QUIC exposes the stateless reset token on the network path when using the default HMAC-based connection-ID and stateless-reset-token generators. The reset token for the server's current source connection ID can be derived from bytes that appear as the connection ID in QUIC headers after a source-CID rotation. An on-path attacker observing the headers can use the token to perform a Denial of Service by sending a spoofed Stateless Reset packet. Version 4.2.15.Final patches the issue.

CVSS3: 4.8
debian
около 2 месяцев назад

Netty is a network application framework for development of protocol s ...

CVSS3: 4.8
github
около 2 месяцев назад

Netty: QUIC stateless reset token material exposed through header-visible connection IDs

EPSS

Процентиль: 10%
0.00204
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-200