Netty before 4.2.16.Final SOCKS Proxy Null Byte Injection
Published Aug 22, 2026
6.3
MEDIUMCVSS 4.0
EPSS 0.25%
Description
Netty (io.netty:netty-codec-socks) versions 4.2.0.Final through 4.2.16.Final and 4.1.x through 4.1.136.Final contain null byte, CRLF, and credential injection vulnerabilities in the SOCKS4 (Socks4ClientEncoder) and SOCKS5 (Socks5ClientEncoder) client encoders, which fail to validate domain address and authentication (username/password) fields. An attacker able to control these fields can inject null bytes or CRLF characters to truncate or alter values, potentially enabling domain spoofing, SOCKS4 userid truncation, authentication data injection, and protocol confusion. Fixed in 4.2.17.Final and 4.1.137.Final.
Affected products
-
Affected
- ≥ 0, < 4.1.137.Final
- ≥ 4.2.0.Final, < 4.2.16.Final
Unaffected
- 4.1.137.Final
- 4.2.16.Final
No data.
Exploit Intelligence
exploit-intelligence/agent-client-rhel9
Out of support scope
OpenShift Serverless
openshift-serverless-1/kn-ekb-dispatcher-rhel9
Fix deferred
OpenShift Serverless
openshift-serverless-1/kn-ekb-receiver-rhel9
Fix deferred
OpenShift Serverless
openshift-serverless-1/kn-eventing-integrations-aws-ddb-streams-source-rhel9
Fix deferred
OpenShift Serverless
openshift-serverless-1/kn-eventing-integrations-aws-s3-sink-rhel9
Fix deferred
OpenShift Serverless
openshift-serverless-1/kn-eventing-integrations-aws-s3-source-rhel9
Fix deferred
OpenShift Serverless
openshift-serverless-1/kn-eventing-integrations-aws-sns-sink-rhel9
Fix deferred
OpenShift Serverless
openshift-serverless-1/kn-eventing-integrations-aws-sqs-sink-rhel9
Fix deferred
OpenShift Serverless
openshift-serverless-1/kn-eventing-integrations-aws-sqs-source-rhel9
Fix deferred
OpenShift Serverless
openshift-serverless-1/kn-eventing-integrations-log-sink-rhel9
Fix deferred
OpenShift Serverless
openshift-serverless-1/kn-eventing-integrations-timer-source-rhel9
Fix deferred
Red Hat AMQ Broker 7
netty-codec-socks
Fix deferred
Red Hat Build of Keycloak
keycloak/rhbk-openshift-rhel9
Out of support scope
Red Hat Build of Keycloak
keycloak/rhbk-rhel9-operator
Out of support scope
Red Hat Build of Keycloak
netty-codec-socks
Fix deferred
Red Hat Build of Keycloak
rhbk/keycloak-rhel9
Fix deferred
Red Hat Build of Keycloak
rhbk/keycloak-rhel9-operator
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3
bazel7
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3
bazel8
Fix deferred
Red Hat Fuse 7
netty-codec-socks
Out of support scope
Red Hat JBoss Enterprise Application Platform 7
jboss-eap-7/eap74-els-openjdk11-openshift-rhel8
Out of support scope
Red Hat JBoss Enterprise Application Platform 7
jboss-eap-7/eap74-els-openjdk17-openshift-rhel8
Out of support scope
Red Hat JBoss Enterprise Application Platform 7
jboss-eap-7/eap74-els-openjdk8-openshift-rhel8
Out of support scope
Red Hat JBoss Enterprise Application Platform 7
netty-codec-socks
Out of support scope
Red Hat JBoss Enterprise Application Platform 8
netty-codec-socks
Fix deferred
Red Hat JBoss Enterprise Application Platform Expansion Pack
netty-codec-socks
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-modelmesh-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-spark-operator-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th-torch-cpu-py312-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th-torch-cuda-py312-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th06-cpu-torch210-py312-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th06-cpu-torch291-py312-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th06-cuda130-torch210-py312-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th06-cuda130-torch291-py312-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th06-rocm64-torch291-py312-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-trustyai-service-rhel9
Fix deferred
Red Hat OpenShift Dev Spaces
devspaces/multicluster-redirector-rhel9
Fix deferred
Red Hat OpenShift Dev Spaces
devspaces/openvsx-rhel9
Fix deferred
Red Hat OpenShift Dev Spaces
devspaces/pluginregistry-rhel9
Fix deferred
Red Hat OpenShift Dev Spaces
devspaces/server-rhel9
Fix deferred
Red Hat Satellite 6
candlepin
Fix deferred
Red Hat Single Sign-On 7
netty-codec-socks
Out of support scope
Red Hat build of Apache Camel 4 for Quarkus 3
netty-codec-socks
Fix deferred
Red Hat build of Apache Camel for Spring Boot 4
netty-codec-socks
Fix deferred
Red Hat build of Apicurio Registry 3
netty-codec-socks
Out of support scope
Red Hat build of Debezium 3
netty-codec-socks
Fix deferred
Red Hat build of Quarkus
netty-codec-socks
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Exploit Intelligence | exploit-intelligence/agent-client-rhel9 | Out of support scope | n/a |
| OpenShift Serverless | openshift-serverless-1/kn-ekb-dispatcher-rhel9 | Fix deferred | n/a |
| OpenShift Serverless | openshift-serverless-1/kn-ekb-receiver-rhel9 | Fix deferred | n/a |
| OpenShift Serverless | openshift-serverless-1/kn-eventing-integrations-aws-ddb-streams-source-rhel9 | Fix deferred | n/a |
| OpenShift Serverless | openshift-serverless-1/kn-eventing-integrations-aws-s3-sink-rhel9 | Fix deferred | n/a |
| OpenShift Serverless | openshift-serverless-1/kn-eventing-integrations-aws-s3-source-rhel9 | Fix deferred | n/a |
| OpenShift Serverless | openshift-serverless-1/kn-eventing-integrations-aws-sns-sink-rhel9 | Fix deferred | n/a |
| OpenShift Serverless | openshift-serverless-1/kn-eventing-integrations-aws-sqs-sink-rhel9 | Fix deferred | n/a |
| OpenShift Serverless | openshift-serverless-1/kn-eventing-integrations-aws-sqs-source-rhel9 | Fix deferred | n/a |
| OpenShift Serverless | openshift-serverless-1/kn-eventing-integrations-log-sink-rhel9 | Fix deferred | n/a |
| OpenShift Serverless | openshift-serverless-1/kn-eventing-integrations-timer-source-rhel9 | Fix deferred | n/a |
| Red Hat AMQ Broker 7 | netty-codec-socks | Fix deferred | n/a |
| Red Hat Build of Keycloak | keycloak/rhbk-openshift-rhel9 | Out of support scope | n/a |
| Red Hat Build of Keycloak | keycloak/rhbk-rhel9-operator | Out of support scope | n/a |
| Red Hat Build of Keycloak | netty-codec-socks | Fix deferred | n/a |
| Red Hat Build of Keycloak | rhbk/keycloak-rhel9 | Fix deferred | n/a |
| Red Hat Build of Keycloak | rhbk/keycloak-rhel9-operator | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | bazel7 | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | bazel8 | Fix deferred | n/a |
| Red Hat Fuse 7 | netty-codec-socks | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | jboss-eap-7/eap74-els-openjdk11-openshift-rhel8 | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | jboss-eap-7/eap74-els-openjdk17-openshift-rhel8 | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | jboss-eap-7/eap74-els-openjdk8-openshift-rhel8 | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | netty-codec-socks | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | netty-codec-socks | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | netty-codec-socks | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-modelmesh-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-spark-operator-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th-torch-cpu-py312-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th-torch-cuda-py312-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th06-cpu-torch210-py312-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th06-cpu-torch291-py312-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th06-cuda130-torch210-py312-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th06-cuda130-torch291-py312-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th06-rocm64-torch291-py312-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-trustyai-service-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/multicluster-redirector-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/openvsx-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/pluginregistry-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/server-rhel9 | Fix deferred | n/a |
| Red Hat Satellite 6 | candlepin | Fix deferred | n/a |
| Red Hat Single Sign-On 7 | netty-codec-socks | Out of support scope | n/a |
| Red Hat build of Apache Camel 4 for Quarkus 3 | netty-codec-socks | Fix deferred | n/a |
| Red Hat build of Apache Camel for Spring Boot 4 | netty-codec-socks | Fix deferred | n/a |
| Red Hat build of Apicurio Registry 3 | netty-codec-socks | Out of support scope | n/a |
| Red Hat build of Debezium 3 | netty-codec-socks | Fix deferred | n/a |
| Red Hat build of Quarkus | netty-codec-socks | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Applications utilizing Netty's SOCKS client encoders should implement robust input validation and sanitization for all domain address and authentication credential fields. If SOCKS proxy client functionality is not required by the application, it should be disabled to remove the attack surface.
References (7)
- https://access.redhat.com/security/cve/CVE-2026-62380 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2521308 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-64272 Advisory
- https://github.com/netty/netty/security/advisories/GHSA-cc6x-ffm5-83wf vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-62380
- https://www.cve.org/CVERecord?id=CVE-2026-62380
- https://www.vulncheck.com/advisories/netty-before-final-socks-proxy-null-byte-injection third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-62380 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2521308 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-64272 | Advisory | |
| https://github.com/netty/netty/security/advisories/GHSA-cc6x-ffm5-83wf | vendor-advisoryVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-62380 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-62380 | ||
| https://www.vulncheck.com/advisories/netty-before-final-socks-proxy-null-byte-injection | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data