Violeta Georgieva
18 exploits
Active since Jun 2026
Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion
CVSS 7.5
Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)
CVSS 7.5
Netty codec-haproxy: Signed-Byte Sentinel Collision in HAProxyMessageDecoder Leads to Unbounded Memory Exhaustion
CVSS 7.5
Netty SpdyHttpDecoder: ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustion
CVSS 7.5
Netty: XML External Entity (XXE) injection via unconfigured XML factory when DTD and entity processing are enabled
CVSS 9.8
Netty: Missing CertificateID Validation in OCSP Response Allows Replay Attacks
CVSS 7.4
Netty codec-haproxy: Signed-Byte Sentinel Collision in HAProxyMessageDecoder Leads to Unbounded Memory Exhaustion
CVSS 7.5
Netty SpdyHttpDecoder: ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustion
CVSS 7.5
Netty: Memory Exhaustion via HTTP/3 Reserved Frame Types
CVSS 7.5
Netty: XML External Entity (XXE) injection via unconfigured XML factory when DTD and entity processing are enabled
CVSS 9.8
Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)
CVSS 7.5
Netty: Missing CertificateID Validation in OCSP Response Allows Replay Attacks
CVSS 7.4
Netty SPDY SETTINGS frame count materializes unbounded settings map
CVSS 7.5
Netty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation
CVSS 7.5
Netty SPDY SETTINGS frame count materializes unbounded settings map
CVSS 7.5
Netty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation
CVSS 7.5
Netty: Denial of Service via Unbounded Headers in StompSubframeDecoder
CVSS 7.5
Netty: Denial of Service via Unbounded Headers in StompSubframeDecoder
CVSS 7.5