Advisories for Maven/Io.netty/Netty-Codec-Stomp package

2026

Netty: STOMP CONNECT Frame Header Injection in Netty

| Field | Value | |——-|——-| | Product | Netty | | Version | 4.2.12.Final (and all prior versions with codec-stomp) | | Component | io.netty.handler.codec.stomp.StompSubframeEncoder | | Vulnerability Type | CWE-93: Improper Neutralization of CRLF Sequences / CWE-113: Improper Neutralization of CRLF in HTTP Headers | | Impact | STOMP Header Injection / Authentication Bypass | | CVSS 3.1 Score | 6.5 (Medium) | | CVSS 3.1 Vector | …