Norman Maurer
20 exploits
Active since Feb 2021
netty-incubator-codec-ohttp OHttpVersionChunkDraft's Missing Final-Chunk Enforcement Leads to Undetected Stream Truncation
netty-incubator-codec-ohttp's HPKEContext operations may produce empty byte[] on failures
CVSS 5.3
netty-incubator-codec-ohttp's Incorrect Native Pointer Derivation in Pooled Direct ByteBuf Fallback Leads to Out-of-Bounds Native Memory Access
CVSS 9.1
Netty: epoll transport denial of service via RST on half-closed TCP connection
CVSS 7.5
HTTP/2 - Denial of Service via Rapid Stream Reset
CVSS 7.5
Netty <4.1.59.Final - Info Disclosure
CVSS 6.2
Netty < 4.1.60 - HTTP Request Smuggling via HTTP/2 to HTTP/1.1 Conversion
CVSS 5.9
Netty < 4.1.61 - HTTP Request Smuggling via Single Http2HeaderFrame
CVSS 5.9
Netty <4.1.71.Final - HTTP Request Smuggling
CVSS 6.5
Netty < 4.1.77 - Local Information Disclosure via Temporary File Permissions
CVSS 5.5
Netty < 4.1.94 - Denial of Service via SniHandler Heap Allocation
CVSS 6.5
Netty < 4.1.108 - Denial of Service via HttpPostRequestDecoder
CVSS 5.3
netty-incubator-codec-ohttp < 0.0.13 - HTTP Request Smuggling and Injection via BinaryHttpParser
CVSS 8.1
Netty < 4.1.115 - Denial of Service via Environment File Read
CVSS 5.5
Netty <4.1.118.Final - Buffer Overflow
CVSS 7.5
Netty <= 4.1.118.Final - Denial of Service via Environment File Read
CVSS 5.5
Netty QUIC codec <0.0.71. Final - Hash DoS
CVSS 5.3
Netty < 4.1.125 - HTTP Request Smuggling via Inconsistent Chunked Transfer Encoding
CVSS 7.5
Netty < 4.1.125 - Denial of Service via BrotliDecoder Decompression
CVSS 7.5
Netty < 4.1.128.Final and 4.2.0.Alpha1-4.2.7.Final - SMTP Command Injection via CRLF Sequence