CVE-2025-67735Patch(netty / netty)

LOWCVSS 6.5 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch netty netty systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-93

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • netty

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 3 signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
netty

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-11: 3Patch / Workaround · 2026-03-11: 303-11
Signal classification1 categories
Patch
3100.0%
Full discourse3 posts
  • GCP Weekly@gcpweekly
    Patch

    This addresses the following vulnerabilities: CVE-2025-48924 CVE-2025-67735 471016560, 471015664, 471015120 Security fixes for apigee-hybrid-cassandra 7/19

    Post summary

    The text lists several CVE identifiers and notes that security fixes were applied to apigee-hybrid-cassandra on 7/19, indicating patch availability.

    1000074
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    This addresses the following vulnerabilities: CVE-2025-48924 CVE-2025-67735 471502495, 471501875, 471126425 Security fixes for apigee-mart-server 6/19

    Post summary

    Patch notice for apigee‑mart‑server, referencing multiple CVEs and BID numbers, indicating vulnerability fixes are being applied.

    1000075
    1.8K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    v1.15.2 Security Bug ID Description 471502899, 471173561 Security fixes for apigee-synchronizer. This addresses the following vulnerabilities: CVE-2025-48924 CVE-2025-67735 471502752, 471191392 Security fixes for apigee-runtime 5/19

    Post summary

    Release note announces security fixes for Apigee products addressing CVE-2025-48924 and CVE-2025-67735, with no indication of active exploitation or detailed vulnerability information.

    1000078
    1.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnettynetty---

Explore more