CVE-2026-42585Disclosure(netty / netty)

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch netty netty systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-444

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • netty

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
netty

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-13: 3Patch / Workaround · 2026-05-13: 1Technical Details · 2026-05-13: 305-13
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets5 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-42585 Netty is an asynchronous, event-driven network application framework. Prior to http://4.2.13.Final and http://4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, e… https://www.cve.org/CVERecord?id=CVE-2026-42585

    Post summary

    The post indicates that Netty versions before 4.2.13.Final and 4.1.133.Final are vulnerable to an incorrect processing of malformed Transfer‑Encoding (CVE‑2026‑42585), but it does not provide a PoC, exploit code, or patch details.

    00001342
    57.5K followersView on X
  • Infoflowcloud@infoflowcloud
    Patch

    🚨*CVE* CVE-2026-42585 Netty is an asynchronous, event-driven network application framework. Prior to http://4.2.13.Final and http://4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, e… https://www.cve.org/CVERecord?id=CVE-2026-42585 ----- Traducció… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑42585, a malformed Transfer‑Encoding parse issue in Netty that has been fixed in versions 4.2.13.Final and 4.1.133.Final.

    0000032
    77 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42585 Request Smuggling via Malformed Transfer-Encoding in Netty Before http://4.2.13.Final https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42585

    Post summary

    The post announces CVE‑2026‑42585 as a request smuggling flaw in Netty versions prior to 4.2.13.Final, providing only basic technical details without any PoC, exploit code, or patch information.

    0000053
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnettynetty---

Explore more