Skip to content

Vulnerable netty dependencies #701

@alok1111

Description

@alok1111

Bug Report

Transitive netty dependencies bring 3 High and 3 Medium vulnerabilities.
io.netty:netty-handler 4.1.112.Final
CVE-2025-24970
io.netty:netty-codec-http 4.1.112.Final
CVE-2025-58056
CVE-2025-58057
CVE-2025-67735
io.netty:netty-common 4.1.112.Final
CVE-2024-47535
CVE-2025-25193

Versions

  • Driver: 1.1.1.RELEASE

Current Behavior

Multiple vulnerabilities detected

Expected behavior/code

No vulnerabilities detected

Possible Solution

Update netty stack to the latest version.
As a workaround, override "io.projectreactor.netty" % "reactor-netty-core" dependency version to a newer one.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions