Skip to content

🔐 CVE-2025-24970: io.netty:netty-handler:jar:4.1.115.Final:provided #70

@github-actions

Description

@github-actions

Summary

Netty, an asynchronous, event-driven network application framework, has a vulnerability starting in version 4.1.91.Final and prior to version 4.1.118.Final. When a special crafted packet is received via SslHandler it doesn't correctly handle validation of such a packet in all cases which can lead to a native crash. Version 4.1.118.Final contains a patch. As workaround its possible to either disable the usage of the native SSLEngine or change the code manually.

CVE: CVE-2025-24970
CWE: CWE-20

References

Metadata

Metadata

Assignees

Labels

securitySecurity related change

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions