83%
Total Score
43
91
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-179204 New netty-codec-http is vulnerable to HTTP Request Smuggling in versions 4.1.0.Final - 4.1.136.Final and 4.2.0.Final - 4.2.16.Final. | 4.1.0.Final - 4.1.136.Final4.2.0.Final - 4.2.16.Final | High |
CVE-2026-59903 io.netty:netty-codec-http is vulnerable to Use of Cache Containing Sensitive Information in versions 4.2.0.Final - 4.2.16.Final and 0.0.0 - 4.1.136.Final. | 0.0.0 - 4.1.136.Final4.2.0.Final - 4.2.16.Final | Medium |
CVE-2026-59921 io.netty:netty-codec-http is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection') in versions 4.2.0.Final - 4.2.16.Final and 0.0.0 - 4.1.136.Final. | 0.0.0 - 4.1.136.Final4.2.0.Final - 4.2.16.Final | Medium |
CVE-2026-59899 io.netty:netty-codec-http is vulnerable to Allocation of Resources Without Limits or Throttling in versions 4.2.0.Final - 4.2.15.Final and 0.0.0 - 4.1.136.Final. | 0.0.0 - 4.1.136.Final4.2.0.Final - 4.2.15.Final | Medium |
CVE-2026-59898 io.netty:netty-codec-http is vulnerable to Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in versions 4.2.0.Final - 4.2.15.Final and 0.0.0 - 4.1.136.Final. | 0.0.0 - 4.1.136.Final4.2.0.Final - 4.2.15.Final | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
${project.groupId}:netty-codec Version 5.0.0.Alpha2 | — | — |
${project.groupId}:netty-handler Version 5.0.0.Alpha2 | — | — |
com.jcraft:jzlib Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.