PT-2026-79547 · Netty · Netty

CVE-2026-62380

·

Published

2026-08-22

·

Updated

2026-08-22

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Netty (io.netty:netty-codec-socks) versions 4.2.0.Final through 4.2.16.Final Netty (io.netty:netty-codec-socks) versions 4.1.x through 4.1.136.Final
Description Null byte, CRLF, and credential injection issues exist in the SOCKS4 (Socks4ClientEncoder) and SOCKS5 (Socks5ClientEncoder) client encoders due to a failure to validate domain address and authentication fields. An attacker controlling these fields can inject null bytes or CRLF (Carriage Return Line Feed) characters to truncate or alter values. This can lead to domain spoofing, SOCKS4 userid truncation, authentication data injection, and protocol confusion.
Recommendations Update Netty (io.netty:netty-codec-socks) versions 4.2.0.Final through 4.2.16.Final to version 4.2.17.Final. Update Netty (io.netty:netty-codec-socks) versions 4.1.x through 4.1.136.Final to version 4.1.137.Final.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-62380
GHSA-CC6X-FFM5-83WF

Affected Products

Netty