- How many CVEs does Netty have?
- Netty has 82 published CVE records since 2014, including 58 in the last two years.
- How many Netty CVEs are in CISA KEV?
- Yes — 1 of Netty's CVEs are listed in CISA's Known Exploited Vulnerabilities catalog, confirmed exploited in the wild and carrying a CISA remediation deadline.
- Which Netty products have the most CVEs?
- The Netty products with the most published CVEs are netty, io.netty:netty-codec-http, io.netty:netty, org.jboss.netty:netty, io.netty:netty-codec-http2.
- What are the most common weakness types in Netty CVEs?
- Netty's CVEs most often map to these CWE weakness types: CWE-400 (Uncontrolled Resource Consumption), CWE-444 (Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')), CWE-770 (Allocation of Resources Without Limits or Throttling), CWE-20 (Improper Input Validation).
- Are there public exploits for Netty vulnerabilities?
- Yes — 29 of Netty's CVEs have a known public exploit.
- How many critical Netty vulnerabilities are there?
- Netty has 8 critical and 44 high-severity CVEs.
- What is the average severity of Netty CVEs?
- The average CVSS base score across Netty's scored CVEs is 7.2.