Michael[verified]@woollardm8Exploit
DepthFirst’s post on CVE-2025-59419 details the discovery, provides a functional PoC/exploit, and references vendor patches, but does not report active exploitation in the wild.
DFIR Lab[verified]@DFIR_LabPatch
The tweet highlights that Netty's SMTP command-name field still lacks proper CRLF validation, indicating the fix for CVE‑2025‑59419 remains incomplete and a more complete patch is needed.
reverseame@reverseameDisclosure
The tweet announces a new zero‑day SMTP injection vulnerability in Netty (CVE-2025-59419), providing its classification and severity but no exploit, mitigation, or active usage details.
CVE@CVEnewDisclosure
The tweet discloses CVE-2026-93576 affecting Netty’s netty‑codec‑smtp, noting that the SMTP command‑name field lacks proper CRLF validation, representing an incomplete fix for a prior CVE.