{"document":{"aggregate_severity":{"text":"hoch"},"category":"csaf_base","csaf_version":"2.0","distribution":{"tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"de-DE","notes":[{"category":"legal_disclaimer","text":"Das BSI ist als Anbieter für die eigenen, zur Nutzung bereitgestellten Inhalte nach den allgemeinen Gesetzen verantwortlich. Nutzerinnen und Nutzer sind jedoch dafür verantwortlich, die Verwendung und/oder die Umsetzung der mit den Inhalten bereitgestellten Informationen sorgfältig im Einzelfall zu prüfen."},{"category":"description","text":"Netty ist ein asynchrones, ereignisgesteuertes Netzwerk-Anwendungs-Framework für die schnelle Entwicklung von wartbaren, hochleistungsfähigen Protokollservern und -clients.","title":"Produktbeschreibung"},{"category":"summary","text":"Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Netty ausnutzen, um Denial-of-Service-Zustände zu verursachen, Sicherheitsmaßnahmen zu umgehen, Request- oder Response-Smuggling durchzuführen sowie Daten offenzulegen oder zu manipulieren.","title":"Angriff"},{"category":"general","text":"- Sonstiges\n- UNIX","title":"Betroffene Betriebssysteme"}],"publisher":{"category":"other","contact_details":"csaf-provider@cert-bund.de","name":"Bundesamt für Sicherheit in der Informationstechnik","namespace":"https://www.bsi.bund.de"},"references":[{"category":"self","summary":"WID-SEC-W-2026-3291 - CSAF Version","url":"https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3291.json"},{"category":"self","summary":"WID-SEC-2026-3291 - Portal Version","url":"https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3291"},{"category":"external","summary":"Netty Security Advisories vom 2026-09-09","url":"https://github.com/netty/netty/security/advisories"},{"category":"external","summary":"GitHub Security Advisory GHSA-2g37-3h88-55hc vom 2026-09-09","url":"https://github.com/netty/netty/security/advisories/GHSA-2g37-3h88-55hc"},{"category":"external","summary":"GitHub Security Advisory GHSA-45h4-vhwh-fmhg vom 2026-09-09","url":"https://github.com/netty/netty/security/advisories/GHSA-45h4-vhwh-fmhg"},{"category":"external","summary":"GitHub Security Advisory GHSA-495p-pchh-r4mc vom 2026-09-09","url":"https://github.com/netty/netty/security/advisories/GHSA-495p-pchh-r4mc"},{"category":"external","summary":"GitHub Security Advisory GHSA-5vh9-c45f-rf7p vom 2026-09-09","url":"https://github.com/netty/netty/security/advisories/GHSA-5vh9-c45f-rf7p"},{"category":"external","summary":"GitHub Security Advisory GHSA-8352-h356-c9qh vom 2026-09-09","url":"https://github.com/netty/netty/security/advisories/GHSA-8352-h356-c9qh"},{"category":"external","summary":"GitHub Security Advisory GHSA-8whp-c7w8-2m72 vom 2026-09-09","url":"https://github.com/netty/netty/security/advisories/GHSA-8whp-c7w8-2m72"},{"category":"external","summary":"GitHub Security Advisory GHSA-cg2g-fxr4-mg8m vom 2026-09-09","url":"https://github.com/netty/netty/security/advisories/GHSA-cg2g-fxr4-mg8m"},{"category":"external","summary":"GitHub Security Advisory GHSA-f64r-x647-cg8w vom 2026-09-09","url":"https://github.com/netty/netty/security/advisories/GHSA-f64r-x647-cg8w"},{"category":"external","summary":"GitHub Security Advisory GHSA-ghg5-c4jg-8q5j vom 2026-09-09","url":"https://github.com/netty/netty/security/advisories/GHSA-ghg5-c4jg-8q5j"},{"category":"external","summary":"GitHub Security Advisory GHSA-h75q-xqrh-59rf vom 2026-09-09","url":"https://github.com/netty/netty/security/advisories/GHSA-h75q-xqrh-59rf"},{"category":"external","summary":"GitHub Security Advisory GHSA-hcvj-94mj-jp5c vom 2026-09-09","url":"https://github.com/netty/netty/security/advisories/GHSA-hcvj-94mj-jp5c"},{"category":"external","summary":"GitHub Security Advisory GHSA-hfr2-x62w-v49h vom 2026-09-09","url":"https://github.com/netty/netty/security/advisories/GHSA-hfr2-x62w-v49h"},{"category":"external","summary":"GitHub Security Advisory GHSA-hmf3-49g9-g7qq vom 2026-09-09","url":"https://github.com/netty/netty/security/advisories/GHSA-hmf3-49g9-g7qq"},{"category":"external","summary":"GitHub Security Advisory GHSA-j4mg-hqgv-34qc vom 2026-09-09","url":"https://github.com/netty/netty/security/advisories/GHSA-j4mg-hqgv-34qc"},{"category":"external","summary":"GitHub Security Advisory GHSA-j58c-g352-8h4p vom 2026-09-09","url":"https://github.com/netty/netty/security/advisories/GHSA-j58c-g352-8h4p"},{"category":"external","summary":"GitHub Security Advisory GHSA-jgph-cgq3-c627 vom 2026-09-09","url":"https://github.com/netty/netty/security/advisories/GHSA-jgph-cgq3-c627"},{"category":"external","summary":"GitHub Security Advisory GHSA-jhjp-5q4f-8wr2 vom 2026-09-09","url":"https://github.com/netty/netty/security/advisories/GHSA-jhjp-5q4f-8wr2"},{"category":"external","summary":"GitHub Security Advisory GHSA-jj3c-mwvr-9g52 vom 2026-09-09","url":"https://github.com/netty/netty/security/advisories/GHSA-jj3c-mwvr-9g52"},{"category":"external","summary":"GitHub Security Advisory GHSA-jqf3-r9ww-c5x8 vom 2026-09-09","url":"https://github.com/netty/netty/security/advisories/GHSA-jqf3-r9ww-c5x8"},{"category":"external","summary":"GitHub Security Advisory GHSA-mj35-3qqm-q387 vom 2026-09-09","url":"https://github.com/netty/netty/security/advisories/GHSA-mj35-3qqm-q387"},{"category":"external","summary":"GitHub Security Advisory GHSA-pq4x-537v-r54q vom 2026-09-09","url":"https://github.com/netty/netty/security/advisories/GHSA-pq4x-537v-r54q"},{"category":"external","summary":"GitHub Security Advisory GHSA-pvjx-v7vp-62vq vom 2026-09-09","url":"https://github.com/netty/netty/security/advisories/GHSA-pvjx-v7vp-62vq"},{"category":"external","summary":"GitHub Security Advisory GHSA-q9pg-8h3j-8hvm vom 2026-09-09","url":"https://github.com/netty/netty/security/advisories/GHSA-q9pg-8h3j-8hvm"},{"category":"external","summary":"GitHub Security Advisory GHSA-r4xx-7fpg-j8xg vom 2026-09-09","url":"https://github.com/netty/netty/security/advisories/GHSA-r4xx-7fpg-j8xg"},{"category":"external","summary":"GitHub Security Advisory GHSA-rmcw-9fcq-wjq7 vom 2026-09-09","url":"https://github.com/netty/netty/security/advisories/GHSA-rmcw-9fcq-wjq7"},{"category":"external","summary":"GitHub Security Advisory GHSA-rq4j-fc47-9698 vom 2026-09-09","url":"https://github.com/netty/netty/security/advisories/GHSA-rq4j-fc47-9698"},{"category":"external","summary":"GitHub Security Advisory GHSA-v5p2-hmgx-3xrx vom 2026-09-09","url":"https://github.com/netty/netty/security/advisories/GHSA-v5p2-hmgx-3xrx"},{"category":"external","summary":"GitHub Security Advisory GHSA-w6j8-x45j-w75f vom 2026-09-09","url":"https://github.com/netty/netty/security/advisories/GHSA-w6j8-x45j-w75f"},{"category":"external","summary":"GitHub Security Advisory GHSA-wxrh-4rgq-pjcg vom 2026-09-09","url":"https://github.com/netty/netty/security/advisories/GHSA-wxrh-4rgq-pjcg"}],"source_lang":"en-US","title":"Netty: Mehrere Schwachstellen","tracking":{"current_release_date":"2026-09-09T22:00:00.000+00:00","generator":{"date":"2026-09-10T12:46:36.631+00:00","engine":{"name":"BSI-WID","version":"1.6.0"}},"id":"WID-SEC-W-2026-3291","initial_release_date":"2026-09-09T22:00:00.000+00:00","revision_history":[{"date":"2026-09-09T22:00:00.000+00:00","number":"1","summary":"Initiale Fassung"}],"status":"final","version":"1"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_version_range","name":"<4.2.18.Final","product":{"name":"Open Source Netty <4.2.18.Final","product_id":"T059338"}},{"category":"product_version","name":"4.2.18.Final","product":{"name":"Open Source Netty 4.2.18.Final","product_id":"T059338-fixed","product_identification_helper":{"cpe":"cpe:/a:netty:netty:4.2.18.final"}}},{"category":"product_version_range","name":"<4.1.138.Final","product":{"name":"Open Source Netty <4.1.138.Final","product_id":"T059339"}},{"category":"product_version","name":"4.1.138.Final","product":{"name":"Open Source Netty 4.1.138.Final","product_id":"T059339-fixed","product_identification_helper":{"cpe":"cpe:/a:netty:netty:4.1.138.final"}}}],"category":"product_name","name":"Netty"}],"category":"vendor","name":"Open Source"}]},"vulnerabilities":[{"product_status":{"known_affected":["T059339","T059338"]},"release_date":"2026-09-09T22:00:00.000+00:00"}]}