Loading market data...
← Back to CVE feed

CVE-2026-42580

MEDIUM CVSS 6.5 View on NVD ↗

Description

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Published: May 13, 2026 19:17 UTC Modified: May 14, 2026 16:26 UTC