CVE-2026-62380
Netty (io.netty:netty-codec-socks) versions 4.2.0.Final through 4.2.16.Final and 4.1.x through 4.1.136.Final contain null byte, CRLF, and credential injection vulnerabilities in the SOCKS4 (Socks4ClientEncoder) and SOCKS5 (Socks5ClientEncoder) client encoders, which fail to validate domain address and authentication (username/password) fields. An attacker able to control these fields can inject null bytes or CRLF characters to truncate or alter values, potentially enabling domain spoofing, SOCKS4 userid truncation, authentication data injection, and protocol confusion. Fixed in 4.2.17.Final and 4.1.137.Final.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N
- EPSS probability
- 0.25%
- CWE
- CWE-626
- Published
- 2026-08-22
- Last modified
- 2026-08-26
Affected products
- netty netty
- netty netty
- netty netty
- netty netty
Weakness type
Related vulnerabilities
- CVE-2026-76816 — Netty: MQTT Topic Name and Client ID Validation Bypass
- CVE-2026-42579 — Netty: DNS Codec Input Validation Bypass in Netty (Encoder + Decoder)
- CVE-2026-42040 — Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams
- CVE-2020-10773 — A stack information leak flaw was found in s390/s390x in the Linux kernel’s memory manager...
- CVE-2019-17137 — This vulnerability allows network-adjacent attackers to bypass authentication on affected...
- CVE-2019-11936 — Various APC functions accept keys containing null bytes as input, leading to premature truncation...