netty-codec-socks is vulnerable to Null Byte Injection
75
High Risk
Netty's SOCKS4 and SOCKS5 client encoders write domain, userid, and credential fields without rejecting null bytes or CRLF sequences. In SOCKS5 a null byte truncates the intended hostname, allowing domain spoofing, and null or CRLF in credentials can bypass authentication. In SOCKS4 embedded nulls in the userid or domain create protocol ambiguity and redirect connections to unintended targets. The fix validates these fields during encoding.
You are affected if you are using a version that falls within the vulnerable range and your application builds SOCKS4/5 requests with externally influenced domain, user, or credential fields.
netty-codec-socks is vulnerable to Null Byte Injection in versions 4.1.0.Final - 4.1.136.Final and 4.2.0.Final - 4.2.16.Final.
Upgrade the io.netty:netty-codec-socks library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.