Norman Maurer
37 exploits
Active since Feb 2021
Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)
CVSS 7.5
Netty codec-haproxy: Signed-Byte Sentinel Collision in HAProxyMessageDecoder Leads to Unbounded Memory Exhaustion
CVSS 7.5
Netty SpdyHttpDecoder: ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustion
CVSS 7.5
Netty: XML External Entity (XXE) injection via unconfigured XML factory when DTD and entity processing are enabled
CVSS 9.8
Netty: Missing CertificateID Validation in OCSP Response Allows Replay Attacks
CVSS 7.4
Netty codec-haproxy: Signed-Byte Sentinel Collision in HAProxyMessageDecoder Leads to Unbounded Memory Exhaustion
CVSS 7.5
Netty SpdyHttpDecoder: ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustion
CVSS 7.5
Netty: Memory Exhaustion via HTTP/3 Reserved Frame Types
CVSS 7.5
Netty: XML External Entity (XXE) injection via unconfigured XML factory when DTD and entity processing are enabled
CVSS 9.8
Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)
CVSS 7.5
Netty: Missing CertificateID Validation in OCSP Response Allows Replay Attacks
CVSS 7.4
Netty SPDY SETTINGS frame count materializes unbounded settings map
CVSS 7.5
Netty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation
CVSS 7.5
Netty SPDY SETTINGS frame count materializes unbounded settings map
CVSS 7.5
Netty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation
CVSS 7.5
Netty: Denial of Service via Unbounded Headers in StompSubframeDecoder
CVSS 7.5
Netty: Denial of Service via Unbounded Headers in StompSubframeDecoder
CVSS 7.5
netty-incubator-codec-ohttp OHttpVersionChunkDraft's Missing Final-Chunk Enforcement Leads to Undetected Stream Truncation
netty-incubator-codec-ohttp's HPKEContext operations may produce empty byte[] on failures
CVSS 5.3
netty-incubator-codec-ohttp's Incorrect Native Pointer Derivation in Pooled Direct ByteBuf Fallback Leads to Out-of-Bounds Native Memory Access
CVSS 9.1
Netty: epoll transport denial of service via RST on half-closed TCP connection
CVSS 7.5
HTTP/2 - Denial of Service via Rapid Stream Reset
CVSS 7.5
Netty <4.1.59.Final - Info Disclosure
CVSS 6.2
Netty < 4.1.60 - HTTP Request Smuggling via HTTP/2 to HTTP/1.1 Conversion
CVSS 5.9
Netty < 4.1.61 - HTTP Request Smuggling via Single Http2HeaderFrame
CVSS 5.9