CVE-2026-42584Patch(netty / netty)

LOWCVSS 9.1 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch netty netty systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-444

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • netty

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-05-14)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
netty

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-13: 1Mentions · 2026-05-14: 2Patch / Workaround · 2026-05-14: 2Technical Details · 2026-05-14: 105-1305-14
Signal classification2 categories
Patch
266.7%
General
133.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-05-131
General1
2026-05-142
Patch2
Full discourse3 posts
  • CVE@CVEnew
    Patch

    CVE-2026-42584 Netty is an asynchronous, event-driven network application framework. Prior to http://4.2.13.Final and http://4.1.133.Final, HttpClientCodec pairs each inbound response with an out… https://www.cve.org/CVERecord?id=CVE-2026-42584

    Post summary

    The message cites CVE‑2026‑42584 and indicates it is addressed in Netty 4.2.13.Final and 4.1.133.Final, but lacks detail about exploit or vulnerability type.

    00010498
    57.5K followersView on X
  • Infoflowcloud@infoflowcloud
    Patch

    🚨*CVE* CVE-2026-42584 Netty is an asynchronous, event-driven network application framework. Prior to http://4.2.13.Final and http://4.1.133.Final, HttpClientCodec pairs each inbound response with an out… https://www.cve.org/CVERecord?id=CVE-2026-42584 ----- Traducció… http://infoflow.cloud`

    Post summary

    The tweet references CVE-2026-42584 in Netty, indicates that newer releases (4.2.13.Final and 4.1.133.Final) likely contain a fix, and provides a brief technical detail, but no exploit or PoC information.

    0000044
    77 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-42584 HTTP Response Parsing Vulnerability in Netty Prior to 4.2.13.Fina... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42584 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The post simply references CVE‑2026‑42584 and links to a detail page, without any PoC, exploit code, patch information, or active exploitation claims.

    0000043
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnettynetty---

Explore more