Netty 4.2.16.Final 发布,Java 网络应用框架
Netty 是一个异步事件驱动的网络应用框架,主要用于可维护的高性能协议服务器和客户端的快速开发。Netty 4.2.16.Final 现已发布,这是一个修复漏洞和安全问题的版本。
### 修复的安全问题
- [CVE-2026-XXXXX](https://github.com/netty/netty/security/advisories/GHSA-vhch-2wf3-m8rp):`io.netty:netty-codec-stomp`内存耗尽。
- [CVE-2026-55833](https://github.com/netty/netty/security/advisories/GHSA-mvh2-crg5-v77c):`io.netty:netty-codec-http`中的 zip bomb。
- [CVE-2026-XXXXX](https://github.com/netty/netty/security/advisories/GHSA-gcjf-9mgh-3p7g):`io.netty:netty-codec-http`中 CR/LF neutralization 不当(multipart)。
- [CVE-2026-XXXXX](https://github.com/netty/netty/security/advisories/GHSA-wh89-7897-x99h):`io.netty:netty-codec-haproxy`中 CR/LF neutralization 不当。
- [CVE-2026-55851](https://github.com/netty/netty/security/advisories/GHSA-q6cq-mhr2-jmr5):`io.netty:netty-codec-haproxy`内存耗尽。
- [CVE-2026-56745](https://github.com/netty/netty/security/advisories/GHSA-jppx-w49h-x2qq):`io.netty:netty-codec-http`内存耗尽。
- [CVE-2026-56817](https://github.com/netty/netty/security/advisories/GHSA-4qhr-g3c6-fcfx):`io.netty:netty-codec-xml`中 XML 解析中的不安全默认值。
- [CVE-2026-XXXXX](https://github.com/netty/netty/security/advisories/GHSA-q4f6-jm68-57ww):`io.netty:netty-codec-http`内存耗尽。
- [CVE-2026-56818](https://github.com/netty/netty/security/advisories/GHSA-p9jm-q85p-7mcp):`io.netty:netty-codec-redis`内存泄漏。
- [CVE-2026-56819](https://github.com/netty/netty/security/advisories/GHSA-93wv-jw9v-4972):`io.netty:netty-codec-http2`内存泄漏。
- [CVE-2026-56816](https://github.com/netty/netty/security/advisories/GHSA-hpcc-26xq-25fv):`io.netty:netty-codec-http3`内存耗尽。
- [CVE-2026-55831](https://github.com/netty/netty/security/advisories/GHSA-6jqx-86gh-f27w):`io.netty:netty-codec-http`资源耗尽/DoS攻击。
- [CVE-2026-XXXXX](https://github.com/netty/netty/security/advisories/GHSA-mfg7-5gfp-c4w3):`io.netty:netty-codec-dns`内存泄漏。
- [CVE-2026-XXXXX](https://github.com/netty/netty/security/advisories/GHSA-558v-64gr-wgg4):`io.netty:netty-codec-compression`中存在无限循环 (bzip2)。
- [CVE-2026-XXXXX](https://github.com/netty/netty/security/advisories/GHSA-c69g-56f8-xwqj):`io.netty:netty-codec-http2`中 header neutralization不当。
- [CVE-2026-XXXXX](https://github.com/netty/netty/security/advisories/GHSA-4mp9-239f-g9hg):`io.netty:netty-codec-http`中的协议版本混淆 (websocket)。
- [CVE-2026-56746](https://github.com/netty/netty/security/advisories/GHSA-6cqp-g7gg-8hr5):`io.netty:netty-codec-http`中访问控制不当(CORS)。
- [CVE-2026-56822](https://github.com/netty/netty/security/advisories/GHSA-wc96-39fc-566f):`io.netty:netty-handler-ssl-ocsp`中的 time-of-check/time-of-use 漏洞。
- [CVE-2026-XXXXX](https://github.com/netty/netty/security/advisories/GHSA-v74w-7mr3-4qg3):`io.netty:netty-codec-xml`不受控制的资源消耗。
- [CVE-2026-56820](https://github.com/netty/netty/security/advisories/GHSA-272m-gcwp-mpwg):`io.netty:netty-handler-ssl-ocsp`证书验证不当。
- [CVE-2026-56821](https://github.com/netty/netty/security/advisories/GHSA-g7hg-vrcf-mvmr):`io.netty:netty-handler-ssl-ocsp`证书吊销检查不当。
- [CVE-2026-XXXXX](https://github.com/netty/netty/security/advisories/GHSA-3g8r-4pfx-jmfh):`io.netty:netty-codec-stomp`中 CR/LF neutrolization 不当。
更多详情可查看:[https://netty.io/news/2026/07/06/4-2-16-Final.html](https://netty.io/news/2026/07/06/4-2-16-Final.html)
---
原文链接:[点击查看](https://www.oschina.net/news/471606/netty-4-2-16-released)
### 修复的安全问题
- [CVE-2026-XXXXX](https://github.com/netty/netty/security/advisories/GHSA-vhch-2wf3-m8rp):`io.netty:netty-codec-stomp`内存耗尽。
- [CVE-2026-55833](https://github.com/netty/netty/security/advisories/GHSA-mvh2-crg5-v77c):`io.netty:netty-codec-http`中的 zip bomb。
- [CVE-2026-XXXXX](https://github.com/netty/netty/security/advisories/GHSA-gcjf-9mgh-3p7g):`io.netty:netty-codec-http`中 CR/LF neutralization 不当(multipart)。
- [CVE-2026-XXXXX](https://github.com/netty/netty/security/advisories/GHSA-wh89-7897-x99h):`io.netty:netty-codec-haproxy`中 CR/LF neutralization 不当。
- [CVE-2026-55851](https://github.com/netty/netty/security/advisories/GHSA-q6cq-mhr2-jmr5):`io.netty:netty-codec-haproxy`内存耗尽。
- [CVE-2026-56745](https://github.com/netty/netty/security/advisories/GHSA-jppx-w49h-x2qq):`io.netty:netty-codec-http`内存耗尽。
- [CVE-2026-56817](https://github.com/netty/netty/security/advisories/GHSA-4qhr-g3c6-fcfx):`io.netty:netty-codec-xml`中 XML 解析中的不安全默认值。
- [CVE-2026-XXXXX](https://github.com/netty/netty/security/advisories/GHSA-q4f6-jm68-57ww):`io.netty:netty-codec-http`内存耗尽。
- [CVE-2026-56818](https://github.com/netty/netty/security/advisories/GHSA-p9jm-q85p-7mcp):`io.netty:netty-codec-redis`内存泄漏。
- [CVE-2026-56819](https://github.com/netty/netty/security/advisories/GHSA-93wv-jw9v-4972):`io.netty:netty-codec-http2`内存泄漏。
- [CVE-2026-56816](https://github.com/netty/netty/security/advisories/GHSA-hpcc-26xq-25fv):`io.netty:netty-codec-http3`内存耗尽。
- [CVE-2026-55831](https://github.com/netty/netty/security/advisories/GHSA-6jqx-86gh-f27w):`io.netty:netty-codec-http`资源耗尽/DoS攻击。
- [CVE-2026-XXXXX](https://github.com/netty/netty/security/advisories/GHSA-mfg7-5gfp-c4w3):`io.netty:netty-codec-dns`内存泄漏。
- [CVE-2026-XXXXX](https://github.com/netty/netty/security/advisories/GHSA-558v-64gr-wgg4):`io.netty:netty-codec-compression`中存在无限循环 (bzip2)。
- [CVE-2026-XXXXX](https://github.com/netty/netty/security/advisories/GHSA-c69g-56f8-xwqj):`io.netty:netty-codec-http2`中 header neutralization不当。
- [CVE-2026-XXXXX](https://github.com/netty/netty/security/advisories/GHSA-4mp9-239f-g9hg):`io.netty:netty-codec-http`中的协议版本混淆 (websocket)。
- [CVE-2026-56746](https://github.com/netty/netty/security/advisories/GHSA-6cqp-g7gg-8hr5):`io.netty:netty-codec-http`中访问控制不当(CORS)。
- [CVE-2026-56822](https://github.com/netty/netty/security/advisories/GHSA-wc96-39fc-566f):`io.netty:netty-handler-ssl-ocsp`中的 time-of-check/time-of-use 漏洞。
- [CVE-2026-XXXXX](https://github.com/netty/netty/security/advisories/GHSA-v74w-7mr3-4qg3):`io.netty:netty-codec-xml`不受控制的资源消耗。
- [CVE-2026-56820](https://github.com/netty/netty/security/advisories/GHSA-272m-gcwp-mpwg):`io.netty:netty-handler-ssl-ocsp`证书验证不当。
- [CVE-2026-56821](https://github.com/netty/netty/security/advisories/GHSA-g7hg-vrcf-mvmr):`io.netty:netty-handler-ssl-ocsp`证书吊销检查不当。
- [CVE-2026-XXXXX](https://github.com/netty/netty/security/advisories/GHSA-3g8r-4pfx-jmfh):`io.netty:netty-codec-stomp`中 CR/LF neutrolization 不当。
更多详情可查看:[https://netty.io/news/2026/07/06/4-2-16-Final.html](https://netty.io/news/2026/07/06/4-2-16-Final.html)
---
原文链接:[点击查看](https://www.oschina.net/news/471606/netty-4-2-16-released)
评论
暂无评论。