Логотип exploitDog
bind:"BDU:2025-14439" OR bind:"CVE-2025-59419"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2025-14439" OR bind:"CVE-2025-59419"

Количество 7

Количество 7

fstec логотип

BDU:2025-14439

3 месяца назад

Уязвимость сетевого программного средства Netty, связанная с непринятием мер по чистке данных на управляющем уровне, позволяющая нарушителю выполнять произвольные SMTP-команды

CVSS3: 5.3
EPSS: Низкий
redos логотип

ROS-20251106-02

2 месяца назад

Уязвимость netty

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2025-59419

3 месяца назад

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.128.Final and 4.2.7.Final, the SMTP codec in Netty contains an SMTP command injection vulnerability due to insufficient input validation for Carriage Return (\r) and Line Feed (\n) characters in user-supplied parameters. The vulnerability exists in io.netty.handler.codec.smtp.DefaultSmtpRequest, where parameters are directly concatenated into the SMTP command string without sanitization. When methods such as SmtpRequests.rcpt(recipient) are called with a malicious string containing CRLF sequences, attackers can inject arbitrary SMTP commands. Because the injected commands are sent from the server's trusted IP address, resulting emails will likely pass SPF and DKIM authentication checks, making them appear legitimate. This allows remote attackers who can control SMTP command parameters (such as email recipients) to forge arbitrary emails from the trusted server, potentially impersonating ex...

EPSS: Низкий
nvd логотип

CVE-2025-59419

3 месяца назад

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.128.Final and 4.2.7.Final, the SMTP codec in Netty contains an SMTP command injection vulnerability due to insufficient input validation for Carriage Return (\r) and Line Feed (\n) characters in user-supplied parameters. The vulnerability exists in io.netty.handler.codec.smtp.DefaultSmtpRequest, where parameters are directly concatenated into the SMTP command string without sanitization. When methods such as SmtpRequests.rcpt(recipient) are called with a malicious string containing CRLF sequences, attackers can inject arbitrary SMTP commands. Because the injected commands are sent from the server's trusted IP address, resulting emails will likely pass SPF and DKIM authentication checks, making them appear legitimate. This allows remote attackers who can control SMTP command parameters (such as email recipients) to forge arbitrary emails from the trusted server, potentially impersonating execu

EPSS: Низкий
debian логотип

CVE-2025-59419

3 месяца назад

Netty is an asynchronous, event-driven network application framework. ...

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:4087-1

2 месяца назад

Security update for netty, netty-tcnative

EPSS: Низкий
github логотип

GHSA-jq43-27x9-3v86

3 месяца назад

Netty has SMTP Command Injection Vulnerability that Allows Email Forgery

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2025-14439

Уязвимость сетевого программного средства Netty, связанная с непринятием мер по чистке данных на управляющем уровне, позволяющая нарушителю выполнять произвольные SMTP-команды

CVSS3: 5.3
3%
Низкий
3 месяца назад
redos логотип
ROS-20251106-02

Уязвимость netty

CVSS3: 5.3
3%
Низкий
2 месяца назад
ubuntu логотип
CVE-2025-59419

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.128.Final and 4.2.7.Final, the SMTP codec in Netty contains an SMTP command injection vulnerability due to insufficient input validation for Carriage Return (\r) and Line Feed (\n) characters in user-supplied parameters. The vulnerability exists in io.netty.handler.codec.smtp.DefaultSmtpRequest, where parameters are directly concatenated into the SMTP command string without sanitization. When methods such as SmtpRequests.rcpt(recipient) are called with a malicious string containing CRLF sequences, attackers can inject arbitrary SMTP commands. Because the injected commands are sent from the server's trusted IP address, resulting emails will likely pass SPF and DKIM authentication checks, making them appear legitimate. This allows remote attackers who can control SMTP command parameters (such as email recipients) to forge arbitrary emails from the trusted server, potentially impersonating ex...

3%
Низкий
3 месяца назад
nvd логотип
CVE-2025-59419

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.128.Final and 4.2.7.Final, the SMTP codec in Netty contains an SMTP command injection vulnerability due to insufficient input validation for Carriage Return (\r) and Line Feed (\n) characters in user-supplied parameters. The vulnerability exists in io.netty.handler.codec.smtp.DefaultSmtpRequest, where parameters are directly concatenated into the SMTP command string without sanitization. When methods such as SmtpRequests.rcpt(recipient) are called with a malicious string containing CRLF sequences, attackers can inject arbitrary SMTP commands. Because the injected commands are sent from the server's trusted IP address, resulting emails will likely pass SPF and DKIM authentication checks, making them appear legitimate. This allows remote attackers who can control SMTP command parameters (such as email recipients) to forge arbitrary emails from the trusted server, potentially impersonating execu

3%
Низкий
3 месяца назад
debian логотип
CVE-2025-59419

Netty is an asynchronous, event-driven network application framework. ...

3%
Низкий
3 месяца назад
suse-cvrf логотип
SUSE-SU-2025:4087-1

Security update for netty, netty-tcnative

3%
Низкий
2 месяца назад
github логотип
GHSA-jq43-27x9-3v86

Netty has SMTP Command Injection Vulnerability that Allows Email Forgery

3%
Низкий
3 месяца назад

Уязвимостей на страницу