Its single runtime dependency keeps integration relatively simple, and the signed Maven publication adds useful release provenance. The artifact is a focused compiled module, so missing source-oriented files are not concerning here.
88%
Total Score
100
100
100
100
All health scores are okay.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-710075 New netty-codec-haproxy is vulnerable to Memory Leak in versions 0.0.1 - 4.1.137.Final and 0.0.1 - 4.2.17.Final. | 0.0.1 - 4.2.17.Final | Medium |
CVE-2026-59919 io.netty:netty-codec-haproxy is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection') in versions 4.2.0.Final - 4.2.16.Final and 0.0.0 - 4.1.136.Final. | 0.0.0 - 4.1.136.Final4.2.0.Final - 4.2.16.Final | Medium |
CVE-2026-55851 io.netty:netty-codec-haproxy is vulnerable to Uncontrolled Resource Consumption in versions 4.2.0.Final - 4.2.15.Final and 4.1.0.Final - 4.1.135.Final. | 4.1.0.Final - 4.1.135.Final4.2.0.Final - 4.2.15.Final | High |
CVE-2026-48059 io.netty:netty-codec-haproxy is vulnerable to Missing Release of Memory after Effective Lifetime in versions 4.2.0.Final - 4.2.14.Final and 0.0.0 - 4.1.134.Final. | 0.0.0 - 4.1.134.Final4.2.0.Final - 4.2.14.Final | High |
CVE-2026-44893 io.netty:netty-codec-haproxy is vulnerable to Improper Check or Handling of Exceptional Conditions in versions 4.2.0.Final - 4.2.14.Final and 0.0.0 - 4.1.134.Final. | 0.0.0 - 4.1.134.Final4.2.0.Final - 4.2.14.Final | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
${project.groupId}:netty-codec Version 5.0.0.Alpha2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.