Package Health

io.netty:netty-codec-http3

This release appears healthy and suitable to depend on: it is actively released, stable, non-deprecated, backed by an unarchived organization-owned repository with strong recent commit and contributor activity, and has Maven PGP build provenance plus repository security tooling and policy. The artifact is a focused compiled Maven module, so its lack of packaged README, tests, and changelog is substantially mitigated by repository tests and GitHub Releases. Some workflow permission hygiene and the repository/package naming mismatch warrant review, but neither outweighs the strong maintenance and backing evidence.

Latest 4.2.18.FinalMavenMaven

91%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

100

Are you affected? Scan for Free

Health Score Breakdown

Dangerous workflowscaution

Three workflows use pull_request_target and one uses workflow_run, which warrants workflow-review caution; however, no untrusted checkouts or script-injection patterns were detected across all 15 analyzed workflows.

Repo package mentioncaution

The repository name does not match the package and its README does not mention the package, creating a caution that the artifact could be associated with a broader repository without explicit package-level identification. The package file tree does show the corresponding HTTP/3 module path, which reduces but does not eliminate that transparency gap.

Token permissionscaution

Six of 15 workflows lack top-level permission declarations and one declares top-level write access, leaving avoidable token-scope ambiguity; eight workflows do declare read-only permissions, which partially offsets the concern.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-110281 New
netty-codec-http3 is vulnerable to Denial of Service (DoS) in versions 4.2.0.Final - 4.2.17.Final.
4.2.0.Final - 4.2.17.Final
High
CVE-2026-56816
io.netty:netty-codec-http3 is vulnerable to Uncontrolled Resource Consumption in versions 0.0.0 - 4.2.16.Final.
0.0.0 - 4.2.16.Final
High
CVE-2026-48748
io.netty:netty-codec-http3 is vulnerable to Allocation of Resources Without Limits or Throttling in versions 4.2.0.Final - 4.2.14.Final.
4.2.0.Final - 4.2.14.Final
High
CVE-2026-44892
io.netty:netty-codec-http3 is vulnerable to Uncontrolled Resource Consumption in versions 4.2.0.Final - 4.2.14.Final.
4.2.0.Final - 4.2.14.Final
High
CVE-2026-42582
io.netty:netty-codec-http3 is vulnerable to Allocation of Resources Without Limits or Throttling in versions 4.2.0.Final - 4.2.12.Final.
4.2.0.Final - 4.2.12.Final
High

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
io.netty:netty-common
Version 4.2.18.Final
io.netty:netty-buffer
Version 4.2.18.Final
io.netty:netty-codec-base
Version 4.2.18.Final
io.netty:netty-codec-http
Version 4.2.18.Final
io.netty:netty-transport
Version 4.2.18.Final

Weekly Downloads

Info

Last Published
12 days ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform