CVE-2025-58057Patch(netty / netty)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch netty netty systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In netty-codec-compression versions 4.1.124.Final and below, and netty-codec versions 4.2.4.Final and below, when supplied with specially crafted input, BrotliDecoder and certain other decompression decoders will allocate a large number of reachable byte buffers, which can lead to denial of service. BrotliDecoder.decompress has no limit in how often it calls pull, decompressing data 64K bytes at a time. The buffers are saved in the output list, and remain reachable until OOM is hit. This is fixed in versions 4.1.125.Final of netty-codec and 4.2.5.Final of netty-codec-compression.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-409

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • netty

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Peaked 1d ago at 2 mentions (2026-03-11); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
netty

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-11: 2Mentions · 2026-03-21: 1Patch / Workaround · 2026-03-11: 2Patch / Workaround · 2026-03-21: 103-1103-21
Signal classification1 categories
Patch
3100.0%
Classification over time
DateTotalLabels
2026-03-112
Patch2
2026-03-211
Patch1
Full discourse3 posts
  • GCP Weekly@gcpweekly
    Patch

    2.2.79-rocky9, 2.2.79-ubuntu22, 2.2.79-ubuntu22-arm 2.3.26-debian12, 2.3.26-ml-ubuntu22, 2.3.26-rocky9, 2.3.26-ubuntu22, 2.3.26-ubuntu22-arm Fixed CVEs CVE-2025-58057, CVE-2025-53864, CVE-2025-68161, CVE-2025-48924, and CVE-2025-33042. Upgraded Dataproc Metastore Proxy to 2/3

    Post summary

    The release notes announce that several CVEs have been fixed in new Dataproc Metastore Proxy versions, with no mention of PoC, exploits, or active exploitation.

    1000032
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    2.2.78-debian12, 2.2.78-rocky9, 2.2.78-ubuntu22, 2.2.78-ubuntu22-arm 2.3.25-debian12, 2.3.25-ml-ubuntu22, 2.3.25-rocky9, 2.3.25-ubuntu22, 2.3.25-ubuntu22-arm Fixed Fixed CVEs CVE-2025-58057, CVE-2025-53864, CVE-2025-68161, CVE-2025-48924 (partial), and CVE-2025-33042. 2/4

    Post summary

    The snippet announces that specific software package versions have fixed multiple CVEs, providing an update that addresses these vulnerabilities.

    1000098
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    2.1.110-ubuntu20-arm 2.2.78-debian12, 2.2.78-rocky9, 2.2.78-ubuntu22, 2.2.78-ubuntu22-arm 2.3.25-debian12, 2.3.25-ml-ubuntu22, 2.3.25-rocky9, 2.3.25-ubuntu22, 2.3.25-ubuntu22-arm Fixed Fixed CVEs CVE-2025-58057, CVE-2025-53864, CVE-2025-68161, CVE-2025-48924 (partial), and 2/4

    Post summary

    The update announces that multiple CVE‑2025 vulnerabilities have been fixed in the specified package versions, indicating that vendor patches are available.

    1000088
    1.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnettynetty---

Explore more