[Git][security-tracker-team/security-tracker][master] Add new netty issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Sep 18 22:33:38 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
6d6d2b53 by Salvatore Bonaccorso at 2026-09-18T23:33:12+02:00
Add new netty issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -135,35 +135,65 @@ CVE-2026-93586 (ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/3e0ff6b63c37844732a4f79700bc58ac5370fa25 (6.9.13-56)
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/742ee222f6df8e7512755a8939b16b90a034a9a7 (6.9.13-56)
CVE-2026-93579 (A flaw was found in Netty's HTTP/2 stack. This vulnerability allows a ...)
- TODO: check
+ - netty <unfixed>
+ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536970
+ NOTE: https://github.com/netty/netty/security/advisories/GHSA-8whp-c7w8-2m72
CVE-2026-93578 (A flaw was found in Netty's Online Certificate Status Protocol (OCSP) ...)
- TODO: check
+ - netty <unfixed>
+ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536969
+ NOTE: https://github.com/netty/netty/security/advisories/GHSA-jhjp-5q4f-8wr2
CVE-2026-93576 (Netty netty-codec-smtp \u2014 SMTP command-name field is not CRLF-vali ...)
- TODO: check
+ - netty <unfixed>
+ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536968
+ NOTE: https://github.com/netty/netty/security/advisories/GHSA-5vh9-c45f-rf7p
CVE-2026-93575 (### Summary Netty's fix for CVE-2026-44248 is incomplete. The decoder ...)
- TODO: check
+ - netty <unfixed>
+ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536967
+ NOTE: https://github.com/netty/netty/security/advisories/GHSA-jqf3-r9ww-c5x8
CVE-2026-93573 (Netty split Transfer-Encoding fields bypass final-chunked validation a ...)
- TODO: check
+ - netty <unfixed>
+ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536964
+ NOTE: https://github.com/netty/netty/security/advisories/GHSA-3jrc-fchc-59pw
CVE-2026-93572 (## Summary `RedisArrayAggregator` recently added `maxElements` and `m ...)
- TODO: check
+ - netty <unfixed>
+ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536963
+ NOTE: https://github.com/netty/netty/security/advisories/GHSA-r4xx-7fpg-j8xg
CVE-2026-93569 (HTTP/1 absolute-form Host mismatch is translated to HTTP/2 :authority, ...)
- TODO: check
+ - netty <unfixed>
+ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536962
+ NOTE: https://github.com/netty/netty/security/advisories/GHSA-cg2g-fxr4-mg8m
CVE-2026-93568 (HTTP/2 and HTTP/3 Extended CONNECT requests are downgraded as regular ...)
- TODO: check
+ - netty <unfixed>
+ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536961
+ NOTE: https://github.com/netty/netty/security/advisories/GHSA-w6j8-x45j-w75f
CVE-2026-93567 (HTTP/1 authority-form CONNECT is translated to malformed HTTP/2 CONNEC ...)
- TODO: check
+ - netty <unfixed>
+ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536955
+ NOTE: https://github.com/netty/netty/security/advisories/GHSA-45h4-vhwh-fmhg
CVE-2026-93566 (### Summary Netty skips strict chunk size line validation when the lin ...)
- TODO: check
+ - netty <unfixed>
+ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536954
+ NOTE: https://github.com/netty/netty/security/advisories/GHSA-rq4j-fc47-9698
CVE-2026-93565 (### Summary `RtspMethods.valueOf()` silently strips trailing control b ...)
- TODO: check
+ - netty <unfixed>
+ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536952
+ NOTE: https://github.com/netty/netty/security/advisories/GHSA-h75q-xqrh-59rf
CVE-2026-93564 (HAProxy PROXY-v2 nested-TLV grandchild ByteBuf reference-count leak (i ...)
- TODO: check
+ - netty <unfixed>
+ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536953
+ NOTE: https://github.com/netty/netty/security/advisories/GHSA-j58c-g352-8h4p
CVE-2026-93563 (Unbounded multi-line response accumulation in SmtpResponseDecoder lead ...)
- TODO: check
+ - netty <unfixed>
+ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536976
+ NOTE: https://github.com/netty/netty/security/advisories/GHSA-pq4x-537v-r54q
CVE-2026-93561 (Memcache binary codec signed/unsigned type mismatch causes frame desyn ...)
- TODO: check
+ - netty <unfixed>
+ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536949
+ NOTE: https://github.com/netty/netty/security/advisories/GHSA-wxrh-4rgq-pjcg
CVE-2026-93560 (STOMP codec content-length long-to-int truncation causes infinite deco ...)
- TODO: check
+ - netty <unfixed>
+ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2536939
+ NOTE: https://github.com/netty/netty/security/advisories/GHSA-hmf3-49g9-g7qq
CVE-2026-93559 (A vulnerability was identified in Forget-C Jellyfish AI Short Drama St ...)
TODO: check
CVE-2026-93558 (Unbounded Per-Connection Queue Growth in WebSocketServerExtensionHandl ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6d6d2b5332b587a47cc37dd6bca3370a9eb9f3e1
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6d6d2b5332b587a47cc37dd6bca3370a9eb9f3e1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260918/d5ac8b63/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list