Intel

AIKIDO-2026-445867

netty-handler is vulnerable to Improper Check for Unusual or Exceptional Conditions

Improper Check for Unusual or Exceptional ConditionsCVE-2026-75595 Published Aug 27, 2026

91

Critical Risk

This Affects:

JAVAnetty-handler
0.0.0 - 4.1.136.Final
Fixed in 4.1.137.Final
4.2.0.Final - 4.2.16.Final
Fixed in 4.2.17.Final
Are you affected? Scan for Free

TL;DR

Netty contains a vulnerability in TLS ClientHello parsing that can cause the server to select the default SslContext instead of the intended SNI-specific one. In deployments that rely solely on SNI-selected SslContexts to enforce mutual TLS (mTLS), where the default context does not require client certificates and no application-layer certificate validation is performed, a remote attacker may be able to bypass the client certificate requirement for protected routes. Applications that do not use SNI-based SslContext selection, require client certificates in the default context as well, or perform independent certificate validation are not affected.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you rely on SNI-selected SslContexts to enforce mutual TLS (mTLS), where the default SslContext does not require client certificates and no application-layer certificate validation is performed.

Background info

netty-handler is vulnerable to Improper Check for Unusual or Exceptional Conditions in versions 0.0.0 - 4.1.136.Final and 4.2.0.Final - 4.2.16.Final.

How to fix this

Upgrade the io.netty:netty-handler library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform