Usable with caveats: this is a long-established package with frequent recent releases, a stable current line, minimal runtime dependencies, and signed Maven provenance. The release has no detectable license and no declared source repository, reducing transparency before adoption.
68%
Total Score
100
75
100
100
No declared license and no license file were detected in the artifact or repository, leaving the legal terms for reuse unclear and creating a real adoption risk.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-109779 New netty-codec-stomp is vulnerable to Memory Leak in versions 4.1.0.Final - 4.1.137.Final and 4.2.0.Final - 4.2.17.Final. | 4.1.0.Final - 4.1.137.Final4.2.0.Final - 4.2.17.Final | High |
CVE-2026-59920 io.netty:netty-codec-stomp is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection') in versions 4.2.0.Final - 4.2.16.Final and 0.0.0 - 4.1.136.Final. | 0.0.0 - 4.1.136.Final4.2.0.Final - 4.2.16.Final | Medium |
CVE-2026-44891 io.netty:netty-codec-stomp is vulnerable to Uncontrolled Resource Consumption in versions 4.2.0.Alpha1 - 4.2.15.Final and 0.0.0 - 4.1.135.Final. | 0.0.0 - 4.1.135.Final4.2.0.Alpha1 - 4.2.15.Final | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
${project.groupId}:netty-codec Version 5.0.0.Alpha2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.