An open index of dependabot pull requests across open source projects.

io.netty:netty-handler

Ecosystem:
maven
Package URL:
pkg:maven/io.netty:netty-handler
Total PRs:
220 Dependabot PRs
Latest PR:
about 18 hours ago
Unique Repositories:
74 repositories
Unique Repos (30 days):
6 repositories
Security Advisories
Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking
GHSA-3qp7-7mw8-wx86 CVE-2026-44249 HIGH published about 22 hours ago • updated about 19 hours ago
### Summary An attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addre...
Denial of service in Netty
GHSA-9959-6p3m-wxpc CVE-2014-3488 MODERATE published almost 6 years ago • updated 4 days ago
The SslHandler in Netty before 3.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted SSLv2He...
Denial of Service in Netty
GHSA-mm9x-g8pc-w292 CVE-2020-11612 HIGH published almost 6 years ago • updated 4 days ago
The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could sen...
HTTP Request Smuggling in Netty
GHSA-ff2w-cq2g-wv5f CVE-2020-7238 HIGH published over 6 years ago • updated 4 days ago
Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked lin...
SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine
GHSA-4g8c-wm8x-jfhw CVE-2025-24970 HIGH published over 1 year ago • updated 2 days ago
### Impact When a special crafted packet is received via SslHandler it doesn't correctly handle validation of such a packet in all cases which can ...
Recent PRs
Bump the test-tools group with 6 updates

DSpace/DSpace #12566

4.2.12.Final → 4.2.14.Final Patch PR
Closed 9 days ago 1 comment
DSpace
Bump the netty group with 6 updates

ohumbel/jython #18

4.2.13.Final → 4.2.14.Final Patch PR
Open 17 days ago 1 comment
ohumbel
Bump the dependencies group with 3 updates

Olsc/DroidGit #19

4.2.10.Final → 4.2.11.Final Patch PR
Open 3 months ago 1 comment
Olsc
build(deps): bump the all group in /java with 2 updates

vitessio/vitess #19700

4.2.10.Final → 4.2.11.Final Patch PR
Open 3 months ago 1 comment
vitessio
Bump the netty group with 11 updates

IBM/ibm-cos-sdk-java-v2 #39

4.2.9.Final → 4.2.10.Final Patch PR
Closed 3 months ago 1 comment
IBM
Bump the minor group with 2 updates

navikt/aap-api #579

4.2.8.Final → 4.2.9.Final Patch PR
Closed 6 months ago 1 comment
navikt
Bump the netty group with 6 updates

BisonSchweizAG/jython #30

4.1.119.Final → 4.2.7.Final Minor PR
Open 8 months ago 1 comment
BisonSchweizAG
Package Details
Name: io.netty:netty-handler
Ecosystem: maven
PURL Type: maven
Package URL: pkg:maven/io.netty:netty-handler
JSON API: View JSON
Security Advisories

9

Active advisories
HIGH 6
MODERATE 3
View All maven Advisories
Package Information
Description:

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.

Repository: https://github.com/netty/netty
Homepage: http://netty.io/
Latest Release: 4.2.2.Final
about 1 year ago
Dependent Repos: 7,905
Dependent Packages: 1,984
Ranking: Top 0.0962% by dependent repos Top 0.0383% by dependent pkgs
PR Status
Open 95 (43.2%)
Merged 28 (12.7%)
Closed 74 (33.6%)
PR Types
Minor 61 (27.7%)
Patch 136 (61.8%)