CVE-2025-59419Disclosure

MEDIUMCVSS 5.5 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.128.Final and 4.2.7.Final, the SMTP codec in Netty contains an SMTP command injection vulnerability due to insufficient input validation for Carriage Return (\r) and Line Feed (\n) characters in user-supplied parameters. The vulnerability exists in io.netty.handler.codec.smtp.DefaultSmtpRequest, where parameters are directly concatenated into the SMTP command string without sanitization. When methods such as SmtpRequests.rcpt(recipient) are called with a malicious string containing CRLF sequences, attackers can inject arbitrary SMTP commands. Because the injected commands are sent from the server's trusted IP address, resulting emails will likely pass SPF and DKIM authentication checks, making them appear legitimate. This allows remote attackers who can control SMTP command parameters (such as email recipients) to forge arbitrary emails from the trusted server, potentially impersonating executives and forging high-stakes corporate communications. This issue has been patched in versions 4.1.129.Final and 4.2.8.Final. No known workarounds exist.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-93

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 4d ago at 1 mentions (2026-02-06); latest day: 1
  • 5 total mentions across 5 days

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-02-06: 1Mentions · 2026-02-19: 1Mentions · 2026-09-18: 1Mentions · 2026-09-20: 1Mentions · 2026-10-02: 1PoC Mentioned / Linked · 2026-02-06: 1Exploit Tool / Code · 2026-02-06: 1Patch / Workaround · 2026-02-06: 1Patch / Workaround · 2026-09-20: 1Technical Details · 2026-02-06: 1Technical Details · 2026-02-19: 1Technical Details · 2026-09-18: 1Technical Details · 2026-09-20: 102-0602-1909-1809-2010-02
Signal classification3 categories
Disclosure
250.0%
Exploit
125.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-061
Exploit1
2026-02-191
Disclosure1
2026-09-181
Disclosure1
2026-09-201
Patch1
Full discourse5 posts
  • Michael@woollardm8
    Exploit

    https://depthfirst.com/post/casting-a-net-ty-for-bugs-and-catching-a-big-one-cve-2025-59419?utm_source=tldrinfosec&utm_medium=newsletter&utm_campaign=2026Q1_newsletter_TLDRInfoSec&utm_content=secondary_placement&utm_term=blog_post

    Post summary

    DepthFirst’s post on CVE-2025-59419 details the discovery, provides a functional PoC/exploit, and references vendor patches, but does not report active exploitation in the wild.

    00040101
    3.0K followersView on X
  • reverseame@reverseame
    Disclosure

    Casting a Net(ty) for Bugs, and Catching a Big One (CVE-2025-59419) #Netty #CVE202559419 #SMTPInjection #AISecurity #ZeroDay https://depthfirst.com/post/casting-a-net-ty-for-bugs-and-catching-a-big-one-cve-2025-59419

    Post summary

    The tweet announces a new zero‑day SMTP injection vulnerability in Netty (CVE-2025-59419), providing its classification and severity but no exploit, mitigation, or active usage details.

    00010510
    21.6K followersView on X
  • DFIR Lab@DFIR_Lab

    Netty netty-codec-smtp — SMTP command-name field is not CRLF-validated (incomplete fix of CVE-2025-59419) https://t.co/hkUziL1V9X

    0000023
    144 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    Netty netty-codec-smtp — SMTP command-name field is not CRLF-validated (incomplete fix of CVE-2025-59419) https://t.co/wa0ZKhS9Bo

    Post summary

    The tweet highlights that Netty's SMTP command-name field still lacks proper CRLF validation, indicating the fix for CVE‑2025‑59419 remains incomplete and a more complete patch is needed.

    0000029
    139 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-93576 Netty netty-codec-smtp — SMTP command-name field is not CRLF-validated (incomplete fix of CVE-2025-59419) https://www.cve.org/CVERecord?id=CVE-2026-93576

    Post summary

    The tweet discloses CVE-2026-93576 affecting Netty’s netty‑codec‑smtp, noting that the SMTP command‑name field lacks proper CRLF validation, representing an incomplete fix for a prior CVE.

    000001.1K
    58.1K followersView on X

Explore more