VulnScope — package-centric CVE lookup- MEDIUM6.9CVE-2026-50560Netty susceptible to HTTP/2 Reset Attack with different on-the-wire signature
- HIGH7.5Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion
- HIGH7.5Netty: Wrapping plain trust manager silently disables hostname verification
- HIGH7.5Netty: Unbounded pre-allocation in RedisArrayAggregator from RESP array length
- MEDIUM4.8Netty: QUIC stateless reset token material exposed through header-visible connection IDs
- MEDIUM5.3Netty: HttpObjectDecoder skips arbitrary initial control characters when only initial CRLF characters are permitted
- MEDIUM6.5GeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML Entity Resolution
- HIGH7.2GeoServer has an arbitrary file write vulnerability in its Master Password Dump Page
- HIGH7.2GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection
- MEDIUM5.3netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion
- HIGH7.5Acknowledgement extension out of memory
- HIGH8.0Jenkins: Stored XSS vulnerability in node offline cause description
- HIGH8.1In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization
- MEDIUM6.5In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header
- HIGH8.7Netty has Insufficient Bailiwick Validation for NS Records
- MEDIUM5.3Netty HTTP/2: Advertised MAX_CONCURRENT_STREAMS are not enforced
- HIGH7.5Netty: SCTP reassembly nests buffers without bound
- HIGH8.7Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records
- MEDIUM6.8Netty: DNS Cache Poisoning due to Predictable PRNG and Default Static Source Port
- MEDIUM4.0Netty: Unix-socket fd receive leaks descriptors when peer sends two at once
- HIGH7.5Netty: SNI handler pre-allocates up to 16 MiB from nine attacker bytes
- HIGH7.5Netty's Default QUIC token handler accepts any client-supplied token
- HIGH7.5Netty: HAProxy SSL TLV parsing leaks retained slice on invalid TLV length
- HIGH7.5Netty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header Size
- HIGH7.5Netty has Unbounded Direct Memory Consumption in its RedisDecoder