netty-codec-smtp is vulnerable to Denial of Service (DoS)
75
High Risk
SmtpResponseDecoder accumulates SMTP multi-line response continuation lines into an uncapped list. A malicious or MITM SMTP server that withholds the space-separated terminator line and streams unbounded 250-x continuation lines drives the list to grow without bound across decode calls, exhausting the JVM heap. This results in a denial of service for the SMTP client. The fix bounds the accumulated continuation lines.
You are affected if you are using a version that falls within the vulnerable range and your application uses the SMTP client codec against untrusted or MITM-capable SMTP servers.
netty-codec-smtp is vulnerable to Denial of Service (DoS) in versions 4.1.0.Final - 4.1.137.Final and 4.2.0.Final - 4.2.17.Final.
Upgrade the io.netty:netty-codec-smtp library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.