82%
Total Score
43
89
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-739270 New netty-codec-http2 is vulnerable to Denial of Service (DoS) in versions 4.1.0.Final - 4.1.135.Final and 4.2.0 - 4.2.15.Final. | 4.1.0.Final - 4.1.135.Final4.2.0 - 4.2.15.Final | High |
CVE-2026-59900 New io.netty:netty-codec-http2 is vulnerable to Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in versions 4.2.0.Final - 4.2.15.Final and 0.0.0 - 4.1.136.Final. | 0.0.0 - 4.1.136.Final4.2.0.Final - 4.2.15.Final | Medium |
CVE-2026-50560 io.netty:netty-codec-http2 is vulnerable to Allocation of Resources Without Limits or Throttling in versions 4.2.0.Final - 4.2.14.Final and 0.0.0 - 4.1.134.Final. | 0.0.0 - 4.1.134.Final4.2.0.Final - 4.2.14.Final | Medium |
CVE-2026-48043 io.netty:netty-codec-http2 is vulnerable to Uncontrolled Resource Consumption in versions 0.0.0 - 4.1.134.Final and 4.2.0.Alpha1 - 4.2.14.Final. | 0.0.0 - 4.1.134.Final4.2.0.Alpha1 - 4.2.14.Final | Medium |
CVE-2026-47244 io.netty:netty-codec-http2 is vulnerable to Uncontrolled Resource Consumption in versions 4.2.0.Final - 4.2.14.Final and 0.0.0 - 4.1.134.Final. | 0.0.0 - 4.1.134.Final4.2.0.Final - 4.2.14.Final | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
${project.groupId}:netty-codec-http Version 5.0.0.Alpha2 | — | — |
${project.groupId}:netty-handler Version 5.0.0.Alpha2 | — | — |
com.twitter:hpack Version * | — | — |
com.jcraft:jzlib Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant