Netty bug can crash services

Published September 11, 2026

Netty has a CERT-Bund advisory for 13 vulnerabilities in versions before 4.2.13. Final.

Severity
Not scoredNo CVSS score recorded
Fix
Fixed in 4.2.13.FinalFix recorded today
Affected versions
before 4.2.13.Final
Affects
Netty+2 more
Exploited
Not confirmedNo confirmation recorded

How it works

A remote, anonymous attacker can exploit multiple vulnerabilities in Netty to bypass security measures, manipulate data, disclose sensitive information, or cause a denial-of-service condition.

What to do

Check your Netty version. If it is before 4.2.13. Final, this advisory applies.

Update Netty to 4.2.13. Final or newer.

Technical details

Affected software: Netty, Sonstiges, UNIX

CERT-Bund describes Netty as a asynchrones, ereignisgesteuertes Netzwerk-Anwendungs-Framework für die schnelle Entwicklung von wartbaren, hochleistungsfähigen Protokollservern und -clients. A remote, anonymous attacker can exploit multiple vulnerabilities in Netty to bypass security measures, manipulate data, disclose sensitive information, or cause a denial-of-service condition. The advisory tracks CVE-2026-41417, CVE-2026-42577, CVE-2026-42578, CVE-2026-42579, CVE-2026-42580, CVE-2026-42581, CVE-2026-42582, CVE-2026-42583.

In CERT-Bund's CSAF data, affected versions are before 4.2.13. Final, before 4.1.133. Final, and the fixed version is 4.2.13. Final, 4.1.133. Final. Affected operating systems listed by CERT-Bund: Sonstiges, UNIX.

References