๐Ÿ” CVE Alert

CVE-2026-75595

UNKNOWN 0.0

Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.handler.ssl.SslClientHelloHandler#decode checks the wrong offset before reading the four-byte TLS handshake header, so a ClientHello whose handshake header spans records can cause an IndexOutOfBoundsException and invoke select(ctx, null). This selects the default SslContext instead of the SNI-specific context. In deployments where per-SNI clientAuth=REQUIRE is the sole mutual TLS gate, the default SslContext uses clientAuth=NONE or clientAuth=OPTIONAL, and no application-layer certificate verification exists, an unauthenticated remote attacker can bypass the protected route's mutual TLS requirement. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final.

CWE CWE-754
Vendor netty
Product netty
Published Aug 19, 2026
Stay Ahead of the Next One

Get instant alerts for netty netty

Be the first to know when new unknown vulnerabilities affecting netty netty are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

netty / netty
< 4.1.137.Final >= 4.2.0.Final, < 4.2.17.Final

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/netty/netty/security/advisories/GHSA-c4c3-7fpv-j4q5 github.com: https://github.com/netty/netty/pull/17213 github.com: https://github.com/netty/netty/pull/17217 github.com: https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7 github.com: https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961 github.com: https://github.com/netty/netty/releases/tag/netty-4.1.137.Final github.com: https://github.com/netty/netty/releases/tag/netty-4.2.17.Final