netty-incubator-codec-classes-quic is vulnerable to Inefficient Algorithmic Complexity
57
Medium Risk
Affected versions of this package are vulnerable to a hash collision attack in the connection management codec. Remote attackers can trigger a high CPU load on the server —a form of Hash DoS— by initiating multiple connections with specially crafted, colliding Source Connection IDs (SCIDs) that exploit the hash map used for connection tracking.
You are affected if you are using a vulnerable version of the package.
netty-incubator-codec-classes-quic is vulnerable to Inefficient Algorithmic Complexity in versions 0.0.21.Final - 0.0.70.Final.
Upgrade the io.netty.incubator:netty-incubator-codec-classes-quic library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant