Количество 5
Количество 5
CVE-2026-59898
(Netty is an asynchronous, event-driven network application framework. ...)
CVE-2026-59898
A flaw was found in netty-codec-http. The WebSocket handshaker in this component fails to properly validate protocol version information during the WebSocket upgrade process. A remote attacker can exploit this vulnerability by manipulating the WebSocket handshake, leading to a bypass of security checks or the negotiation of unexpected protocol versions. This could potentially enable protocol-level attacks.
CVE-2026-59898
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ab attacker can force WebSocket upgrade via the lax V07 (or V08) handshaker by sending `Sec-WebSocket-Version: 7` and omitting `Connection: Upgrade` / `Upgrade: websocket` headers, completing a protocol switch that a proxy would not recognize as an Upgrade request and enabling HTTP request smuggling / protocol-confusion attacks. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.
CVE-2026-59898
Netty is an asynchronous, event-driven network application framework. ...
GHSA-4mp9-239f-g9hg
Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-59898 (Netty is an asynchronous, event-driven network application framework. ...) | 0% Низкий | 5 дней назад | ||
CVE-2026-59898 A flaw was found in netty-codec-http. The WebSocket handshaker in this component fails to properly validate protocol version information during the WebSocket upgrade process. A remote attacker can exploit this vulnerability by manipulating the WebSocket handshake, leading to a bypass of security checks or the negotiation of unexpected protocol versions. This could potentially enable protocol-level attacks. | CVSS3: 5.3 | 0% Низкий | 26 дней назад | |
CVE-2026-59898 Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ab attacker can force WebSocket upgrade via the lax V07 (or V08) handshaker by sending `Sec-WebSocket-Version: 7` and omitting `Connection: Upgrade` / `Upgrade: websocket` headers, completing a protocol switch that a proxy would not recognize as an Upgrade request and enabling HTTP request smuggling / protocol-confusion attacks. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final. | 0% Низкий | 5 дней назад | ||
CVE-2026-59898 Netty is an asynchronous, event-driven network application framework. ... | 0% Низкий | 5 дней назад | ||
GHSA-4mp9-239f-g9hg Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation | 0% Низкий | 12 дней назад |
Уязвимостей на страницу