Skip to content

[GHSA-c3j3-64rf-grvf] Netty (io.netty:netty-handler) versions from 4.2.0.Final... - #9403

Open
Ankush-Pathak wants to merge 1 commit into
Ankush-Pathak/advisory-improvement-9403from
Ankush-Pathak-GHSA-c3j3-64rf-grvf
Open

[GHSA-c3j3-64rf-grvf] Netty (io.netty:netty-handler) versions from 4.2.0.Final...#9403
Ankush-Pathak wants to merge 1 commit into
Ankush-Pathak/advisory-improvement-9403from
Ankush-Pathak-GHSA-c3j3-64rf-grvf

Conversation

@Ankush-Pathak

@Ankush-Pathak Ankush-Pathak commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

Updates

  • Affected products
  • CVSS v3
  • CVSS v4
  • Summary

Comments
Adding affected Maven coordinates and ranges for io.netty:netty-handler.

Ranges are taken from the netty maintainers' own advisory, published 2026-08-07:
GHSA-p85m-gvr3-788c

  • <= 4.1.136.Final, patched in 4.1.137.Final
  • >= 4.2.0.Final, <= 4.2.16.Final, patched in 4.2.17.Final

Note: the VulnCheck CNA record (https://www.cve.org/CVERecord?id=CVE-2026-62243,
https://www.vulncheck.com/advisories/netty-through-tls-hostname-verification-bypass)
lists 4.2.16.Final as unaffected, which contradicts the maintainer advisory. The
maintainer ranges are used here. The maintainer advisory carries no CVE ID; it
would be worth linking it as the canonical record for this CVE.

Fixed releases:
https://github.com/netty/netty/releases/tag/netty-4.1.137.Final
https://github.com/netty/netty/releases/tag/netty-4.2.17.Final
https://repo1.maven.org/maven2/io/netty/netty-handler/4.1.137.Final/
https://repo1.maven.org/maven2/io/netty/netty-handler/4.2.17.Final/

@github-actions
github-actions Bot changed the base branch from main to Ankush-Pathak/advisory-improvement-9403 September 8, 2026 09:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant