Netty bug can crash services
Netty has a CERT-Bund advisory for 13 vulnerabilities in versions before 4.2.13. Final.
- Severity
- Not scoredNo CVSS score recorded
- Fix
- Fixed in 4.2.13.FinalFix recorded today
- Affected versions
- before 4.2.13.Final
- Affects
- Netty+2 more
- Exploited
- Not confirmedNo confirmation recorded
How it works
A remote, anonymous attacker can exploit multiple vulnerabilities in Netty to bypass security measures, manipulate data, disclose sensitive information, or cause a denial-of-service condition.
What to do
Check your Netty version. If it is before 4.2.13. Final, this advisory applies.
Update Netty to 4.2.13. Final or newer.
Technical details
Affected software: Netty, Sonstiges, UNIX
CERT-Bund describes Netty as a asynchrones, ereignisgesteuertes Netzwerk-Anwendungs-Framework für die schnelle Entwicklung von wartbaren, hochleistungsfähigen Protokollservern und -clients. A remote, anonymous attacker can exploit multiple vulnerabilities in Netty to bypass security measures, manipulate data, disclose sensitive information, or cause a denial-of-service condition. The advisory tracks CVE-2026-41417, CVE-2026-42577, CVE-2026-42578, CVE-2026-42579, CVE-2026-42580, CVE-2026-42581, CVE-2026-42582, CVE-2026-42583.
In CERT-Bund's CSAF data, affected versions are before 4.2.13. Final, before 4.1.133. Final, and the fixed version is 4.2.13. Final, 4.1.133. Final. Affected operating systems listed by CERT-Bund: Sonstiges, UNIX.
References
- wid.cert-bund.de · wid-sec-w-2026-1372.json technical description
- github.com · GHSA-2c5c-chwr-9hqw vendor advisory
- github.com · GHSA-38f8-5428-x5cv vendor advisory
- github.com · GHSA-45q3-82m4-75jr vendor advisory
- github.com · GHSA-57rv-r2g8-2cj3 vendor advisory
- github.com · GHSA-cm33-6792-r9fm vendor advisory
- github.com · GHSA-f6hv-jmp6-3vwv vendor advisory
- github.com · GHSA-jfg9-48mv-9qgx vendor advisory
- github.com · GHSA-m4cv-j2px-7723 vendor advisory
- github.com · GHSA-mj4r-2hfc-f8p6 vendor advisory
- github.com · GHSA-rwm7-x88c-3g2p vendor advisory
- github.com · GHSA-v8h7-rr48-vmmv third party advisory
- github.com · GHSA-v8h7-rr48-vmmv vendor advisory
- github.com · GHSA-xxqh-mfjm-7mv9 vendor advisory
- keycloak.org · keycloak-2663-released third party advisory
- ubuntu.com · USN-8401-1 third party advisory
- lists.suse.com · 026653.html third party advisory
- access.redhat.com · RHSA-2026:24502 third party advisory
- access.redhat.com · RHSA-2026:23808 third party advisory
- access.redhat.com · RHSA-2026:25123 third party advisory
- access.redhat.com · RHSA-2026:28010 third party advisory
- ibm.com · 7277418 third party advisory
- ibm.com · 7277997 third party advisory
- access.redhat.com · RHSA-2026:34608 third party advisory
- access.redhat.com · RHSA-2026:36820 third party advisory
- access.redhat.com · RHSA-2026:37390 third party advisory
- ibm.com · 7279459 third party advisory
- access.redhat.com · RHSA-2026:41951 third party advisory
- access.redhat.com · RHSA-2026:42644 third party advisory
- ibm.com · 7278566 third party advisory
- access.redhat.com · RHSA-2026:50085 third party advisory
- ibm.com · 7282947 third party advisory
- access.redhat.com · RHSA-2026:53806 third party advisory
- access.redhat.com · RHSA-2026:53644 third party advisory
- access.redhat.com · RHSA-2026:54435 third party advisory
- ibm.com · 7283638 third party advisory
- access.redhat.com · RHSA-2026:66545 third party advisory
- access.redhat.com · RHSA-2026:66488 third party advisory