Multiple security vulnerabilities have been identified in netty-handler, which could allow an attacker to bypass SNI routing and trigger quadratic pre-handshake reassembly. The overall risk/impact is moderate to high due to potential exploitation by attackers. Affected version range is 4.2.0 through 4.2.16.
CVE-2026-75596 (CVSS 7.5 — High): A vulnerability in netty-handler allows an attacker to bypass SNI routing via fragmented TLS ClientHello records, causing fallback to the default SslContext.[/subscribe_to_unlock_form]
Multiple security vulnerabilities have been identified in netty-handler, which could allow an attacker to bypass SNI routing and trigger quadratic pre-handshake reassembly. The overall risk/impact is moderate to high due to potential exploitation by attackers. Affected version range is 4.2.0 through 4.2.16.
CVE-2026-75596 (CVSS 7.5 — High): A vulnerability in netty-handler allows an attacker to bypass SNI routing via fragmented TLS ClientHello records, causing fallback to the default SslContext.[emaillocker id="1283"]
CVE-2026-75595 (CVSS 8.1 — Critical): Netty's SNI parsing is vulnerable to quadratic pre-handshake reassembly due to handling of Fragmented ClientHello records, allowing an attacker to potentially trigger a denial-of-service condition.
These vulnerabilities collectively present a significant risk to administrators who have not applied the latest security patches.
We recommend you to update netty-handler to version 4.2.17.Final OR 4.1.137.Final
The following reports contain further technical details:
[/emaillocker]