Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4519-1 | netty security update |
Debian DSA |
DSA-6160-1 | netty security update |
EUVD |
EUVD-2025-26649 | Netty's decoders vulnerable to DoS via zip bomb style attack |
Github GHSA |
GHSA-3p8m-j85q-pgmj | Netty's decoders vulnerable to DoS via zip bomb style attack |
Ubuntu USN |
USN-7918-1 | Netty vulnerabilities |
Mon, 08 Sep 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Thu, 04 Sep 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 04 Sep 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netty
Netty netty |
|
| Vendors & Products |
Netty
Netty netty |
Thu, 04 Sep 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Wed, 03 Sep 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In netty-codec-compression versions 4.1.124.Final and below, and netty-codec versions 4.2.4.Final and below, when supplied with specially crafted input, BrotliDecoder and certain other decompression decoders will allocate a large number of reachable byte buffers, which can lead to denial of service. BrotliDecoder.decompress has no limit in how often it calls pull, decompressing data 64K bytes at a time. The buffers are saved in the output list, and remain reachable until OOM is hit. This is fixed in versions 4.1.125.Final of netty-codec and 4.2.5.Final of netty-codec-compression. | |
| Title | Netty's BrotliDecoder is vulnerable to DoS via zip bomb style attack | |
| Weaknesses | CWE-409 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-09-04T19:59:23.458Z
Reserved: 2025-08-22T14:30:32.221Z
Link: CVE-2025-58057
Updated: 2025-09-04T19:59:19.623Z
Status : Analyzed
Published: 2025-09-04T10:42:32.180
Modified: 2025-09-08T16:45:55.143
Link: CVE-2025-58057
OpenCVE Enrichment
Updated: 2025-09-04T13:12:27Z
Debian DLA
Debian DSA
EUVD
Github GHSA
Ubuntu USN