Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 8

Количество 8

ubuntu логотип

CVE-2026-42582

3 месяца назад

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-42582

3 месяца назад

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-42582

3 месяца назад

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-42582

3 месяца назад

Netty is an asynchronous, event-driven network application framework. ...

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260624-73-0027

около 1 месяца назад

Уязвимость netty

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2c5c-chwr-9hqw

3 месяца назад

Netty HTTP/3 QPACK literal unbounded allocation

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2026-09996

3 месяца назад

Уязвимость компонента io.netty.handler.codec.http3.QpackDecoder фреймворка для разработки сетевых приложений, серверов и клиентов протоколов Netty, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2308-1

около 2 месяцев назад

Security update for netty, netty-tcnative

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-42582

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.

CVSS3: 7.5
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-42582

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.

CVSS3: 7.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-42582

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.

CVSS3: 7.5
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-42582

Netty is an asynchronous, event-driven network application framework. ...

CVSS3: 7.5
0%
Низкий
3 месяца назад
redos логотип
ROS-20260624-73-0027

Уязвимость netty

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-2c5c-chwr-9hqw

Netty HTTP/3 QPACK literal unbounded allocation

CVSS3: 7.5
0%
Низкий
3 месяца назад
fstec логотип
BDU:2026-09996

Уязвимость компонента io.netty.handler.codec.http3.QpackDecoder фреймворка для разработки сетевых приложений, серверов и клиентов протоколов Netty, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
0%
Низкий
3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2308-1

Security update for netty, netty-tcnative

около 2 месяцев назад

Уязвимостей на страницу