[Git][security-tracker-team/security-tracker][master] Add new netty issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 18 22:33:38 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
6d6d2b53 by Salvatore Bonaccorso at 2026-09-18T23:33:12+02:00
Add new netty issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -135,35 +135,65 @@ CVE-2026-93586 (ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-
 	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/3e0ff6b63c37844732a4f79700bc58ac5370fa25 (6.9.13-56)
 	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/742ee222f6df8e7512755a8939b16b90a034a9a7 (6.9.13-56)
 CVE-2026-93579 (A flaw was found in Netty's HTTP/2 stack. This vulnerability allows a  ...)
-	TODO: check
+	- netty <unfixed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536970
+	NOTE: https://github.com/netty/netty/security/advisories/GHSA-8whp-c7w8-2m72
 CVE-2026-93578 (A flaw was found in Netty's Online Certificate Status Protocol (OCSP)  ...)
-	TODO: check
+	- netty <unfixed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536969
+	NOTE: https://github.com/netty/netty/security/advisories/GHSA-jhjp-5q4f-8wr2
 CVE-2026-93576 (Netty netty-codec-smtp \u2014 SMTP command-name field is not CRLF-vali ...)
-	TODO: check
+	- netty <unfixed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536968
+	NOTE: https://github.com/netty/netty/security/advisories/GHSA-5vh9-c45f-rf7p
 CVE-2026-93575 (### Summary Netty's fix for CVE-2026-44248 is incomplete. The decoder  ...)
-	TODO: check
+	- netty <unfixed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536967
+	NOTE: https://github.com/netty/netty/security/advisories/GHSA-jqf3-r9ww-c5x8
 CVE-2026-93573 (Netty split Transfer-Encoding fields bypass final-chunked validation a ...)
-	TODO: check
+	- netty <unfixed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536964
+	NOTE: https://github.com/netty/netty/security/advisories/GHSA-3jrc-fchc-59pw
 CVE-2026-93572 (## Summary  `RedisArrayAggregator` recently added `maxElements` and `m ...)
-	TODO: check
+	- netty <unfixed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536963
+	NOTE: https://github.com/netty/netty/security/advisories/GHSA-r4xx-7fpg-j8xg
 CVE-2026-93569 (HTTP/1 absolute-form Host mismatch is translated to HTTP/2 :authority, ...)
-	TODO: check
+	- netty <unfixed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536962
+	NOTE: https://github.com/netty/netty/security/advisories/GHSA-cg2g-fxr4-mg8m
 CVE-2026-93568 (HTTP/2 and HTTP/3 Extended CONNECT requests are downgraded as regular  ...)
-	TODO: check
+	- netty <unfixed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536961
+	NOTE: https://github.com/netty/netty/security/advisories/GHSA-w6j8-x45j-w75f
 CVE-2026-93567 (HTTP/1 authority-form CONNECT is translated to malformed HTTP/2 CONNEC ...)
-	TODO: check
+	- netty <unfixed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536955
+	NOTE: https://github.com/netty/netty/security/advisories/GHSA-45h4-vhwh-fmhg
 CVE-2026-93566 (### Summary Netty skips strict chunk size line validation when the lin ...)
-	TODO: check
+	- netty <unfixed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536954
+	NOTE: https://github.com/netty/netty/security/advisories/GHSA-rq4j-fc47-9698
 CVE-2026-93565 (### Summary `RtspMethods.valueOf()` silently strips trailing control b ...)
-	TODO: check
+	- netty <unfixed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536952
+	NOTE: https://github.com/netty/netty/security/advisories/GHSA-h75q-xqrh-59rf
 CVE-2026-93564 (HAProxy PROXY-v2 nested-TLV grandchild ByteBuf reference-count leak (i ...)
-	TODO: check
+	- netty <unfixed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536953
+	NOTE: https://github.com/netty/netty/security/advisories/GHSA-j58c-g352-8h4p
 CVE-2026-93563 (Unbounded multi-line response accumulation in SmtpResponseDecoder lead ...)
-	TODO: check
+	- netty <unfixed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536976
+	NOTE: https://github.com/netty/netty/security/advisories/GHSA-pq4x-537v-r54q
 CVE-2026-93561 (Memcache binary codec signed/unsigned type mismatch causes frame desyn ...)
-	TODO: check
+	- netty <unfixed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536949
+	NOTE: https://github.com/netty/netty/security/advisories/GHSA-wxrh-4rgq-pjcg
 CVE-2026-93560 (STOMP codec content-length long-to-int truncation causes infinite deco ...)
-	TODO: check
+	- netty <unfixed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536939
+	NOTE: https://github.com/netty/netty/security/advisories/GHSA-hmf3-49g9-g7qq
 CVE-2026-93559 (A vulnerability was identified in Forget-C Jellyfish AI Short Drama St ...)
 	TODO: check
 CVE-2026-93558 (Unbounded Per-Connection Queue Growth in WebSocketServerExtensionHandl ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6d6d2b5332b587a47cc37dd6bca3370a9eb9f3e1

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6d6d2b5332b587a47cc37dd6bca3370a9eb9f3e1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260918/d5ac8b63/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list