This release appears healthy and suitable to depend on: it is actively released, stable, non-deprecated, backed by an unarchived organization-owned repository with strong recent commit and contributor activity, and has Maven PGP build provenance plus repository security tooling and policy. The artifact is a focused compiled Maven module, so its lack of packaged README, tests, and changelog is substantially mitigated by repository tests and GitHub Releases. Some workflow permission hygiene and the repository/package naming mismatch warrant review, but neither outweighs the strong maintenance and backing evidence.
91%
Total Score
100
100
94
80
100
Three workflows use pull_request_target and one uses workflow_run, which warrants workflow-review caution; however, no untrusted checkouts or script-injection patterns were detected across all 15 analyzed workflows.
The repository name does not match the package and its README does not mention the package, creating a caution that the artifact could be associated with a broader repository without explicit package-level identification. The package file tree does show the corresponding HTTP/3 module path, which reduces but does not eliminate that transparency gap.
Six of 15 workflows lack top-level permission declarations and one declares top-level write access, leaving avoidable token-scope ambiguity; eight workflows do declare read-only permissions, which partially offsets the concern.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-110281 New netty-codec-http3 is vulnerable to Denial of Service (DoS) in versions 4.2.0.Final - 4.2.17.Final. | 4.2.0.Final - 4.2.17.Final | High |
CVE-2026-56816 io.netty:netty-codec-http3 is vulnerable to Uncontrolled Resource Consumption in versions 0.0.0 - 4.2.16.Final. | 0.0.0 - 4.2.16.Final | High |
CVE-2026-48748 io.netty:netty-codec-http3 is vulnerable to Allocation of Resources Without Limits or Throttling in versions 4.2.0.Final - 4.2.14.Final. | 4.2.0.Final - 4.2.14.Final | High |
CVE-2026-44892 io.netty:netty-codec-http3 is vulnerable to Uncontrolled Resource Consumption in versions 4.2.0.Final - 4.2.14.Final. | 4.2.0.Final - 4.2.14.Final | High |
CVE-2026-42582 io.netty:netty-codec-http3 is vulnerable to Allocation of Resources Without Limits or Throttling in versions 4.2.0.Final - 4.2.12.Final. | 4.2.0.Final - 4.2.12.Final | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
io.netty:netty-common Version 4.2.18.Final | — | — |
io.netty:netty-buffer Version 4.2.18.Final | — | — |
io.netty:netty-codec-base Version 4.2.18.Final | — | — |
io.netty:netty-codec-http Version 4.2.18.Final | — | — |
io.netty:netty-transport Version 4.2.18.Final | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.