Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies; false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.

How to read the report | Suppressing false positives | Getting Help: github issues

 Sponsor

Project: Grouper UI

edu.internet2.middleware.grouper:grouper-ui:7.0.0-SNAPSHOT

Scan Information (show all):

Summary

Summary of Vulnerable Dependencies (click to show all)

DependencyVulnerability IDsPackageHighest SeverityCVE CountConfidenceEvidence Count
FastInfoset-1.2.15.jarcpe:2.3:a:fast_ber_project:fast_ber:1.2.15:*:*:*:*:*:*:*pkg:maven/com.sun.xml.fastinfoset/FastInfoset@1.2.15 0Low42
accessors-smart-2.5.2.jarpkg:maven/net.minidev/accessors-smart@2.5.2 043
amqp-client-5.28.0.jarpkg:maven/com.rabbitmq/amqp-client@5.28.0MEDIUM148
angus-activation-2.0.3.jarpkg:maven/org.eclipse.angus/angus-activation@2.0.3 035
angus-mail-2.0.5.jar (shaded: org.eclipse.angus:angus-core:2.0.5)cpe:2.3:a:eclipse:angus_mail:2.0.5:*:*:*:*:*:*:*pkg:maven/org.eclipse.angus/angus-core@2.0.5 0Low9
angus-mail-2.0.5.jar (shaded: org.eclipse.angus:logging-mailhandler:2.0.5)cpe:2.3:a:eclipse:angus_mail:2.0.5:*:*:*:*:*:*:*pkg:maven/org.eclipse.angus/logging-mailhandler@2.0.5 0Highest9
angus-mail-2.0.5.jarcpe:2.3:a:eclipse:angus_mail:2.0.5:*:*:*:*:*:*:*pkg:maven/org.eclipse.angus/angus-mail@2.0.5 0Highest28
animal-sniffer-annotations-1.9.jarpkg:maven/org.codehaus.mojo/animal-sniffer-annotations@1.9 023
annotations-24.0.1.jarpkg:maven/org.jetbrains/annotations@24.0.1 027
ant-1.10.15.jarcpe:2.3:a:apache:ant:1.10.15:*:*:*:*:*:*:*pkg:maven/org.apache.ant/ant@1.10.15 0Highest24
antlr-2.7.7.jarpkg:maven/antlr/antlr@2.7.7 024
asm-7.1.jarpkg:maven/org.ow2.asm/asm@7.1 053
aws-java-sdk-core-1.12.796.jarcpe:2.3:a:amazon:aws-sdk-java:1.12.796:*:*:*:*:*:*:*pkg:maven/com.amazonaws/aws-java-sdk-core@1.12.796 0Highest22
bcpkix-jdk18on-1.84.jarcpe:2.3:a:bouncycastle:bouncy_castle_for_java:1.84:*:*:*:*:*:*:*pkg:maven/org.bouncycastle/bcpkix-jdk18on@1.84HIGH4Highest57
bcprov-jdk18on-1.84.jarcpe:2.3:a:bouncycastle:bouncy_castle_for_java:1.84:*:*:*:*:*:*:*pkg:maven/org.bouncycastle/bcprov-jdk18on@1.84HIGH7Highest49
bcutil-jdk18on-1.84.jarcpe:2.3:a:bouncycastle:bouncy_castle_for_java:1.84:*:*:*:*:*:*:*pkg:maven/org.bouncycastle/bcutil-jdk18on@1.84 0Highest39
bsh-2.0b5.jarcpe:2.3:a:beanshell:beanshell:2.0:b5:*:*:*:*:*:*pkg:maven/org.beanshell/bsh@2.0b5HIGH1Highest27
byte-buddy-1.12.18.jarpkg:maven/net.bytebuddy/byte-buddy@1.12.18 029
c3p0-0.12.0.jarcpe:2.3:a:mchange:c3p0:0.12.0:*:*:*:*:*:*:*pkg:maven/com.mchange/c3p0@0.12.0HIGH1Highest25
c3p0-oracle-thin-extras-0.9.5.jarcpe:2.3:a:mchange:c3p0:0.9.5:*:*:*:*:*:*:*pkg:maven/com.google.code.maven-play-plugin.com.mchange/c3p0-oracle-thin-extras@0.9.5HIGH1Highest29
cglib-3.3.0.jarpkg:maven/cglib/cglib@3.3.0 018
classmate-1.5.1.jarpkg:maven/com.fasterxml/classmate@1.5.1 054
commons-beanutils-1.11.0.jarcpe:2.3:a:apache:commons_beanutils:1.11.0:*:*:*:*:*:*:*pkg:maven/commons-beanutils/commons-beanutils@1.11.0 0Highest170
commons-cli-1.11.0.jarpkg:maven/commons-cli/commons-cli@1.11.0 0102
commons-codec-1.20.0.jarpkg:maven/commons-codec/commons-codec@1.20.0 0121
commons-collections-3.2.2.jarcpe:2.3:a:apache:commons_collections:3.2.2:*:*:*:*:*:*:*pkg:maven/commons-collections/commons-collections@3.2.2 0Highest84
commons-csv-1.14.1.jarpkg:maven/org.apache.commons/commons-csv@1.14.1 087
commons-dbcp-1.4.jarpkg:maven/commons-dbcp/commons-dbcp@1.4 096
commons-digester-2.1.jarpkg:maven/commons-digester/commons-digester@2.1 098
commons-digester3-3.2.jarpkg:maven/org.apache.commons/commons-digester3@3.2 0105
commons-exec-1.6.0.jarpkg:maven/org.apache.commons/commons-exec@1.6.0 066
commons-fileupload-1.6.0.jarcpe:2.3:a:apache:commons_fileupload:1.6.0:*:*:*:*:*:*:*pkg:maven/commons-fileupload/commons-fileupload@1.6.0 0Highest120
commons-io-2.21.0.jarcpe:2.3:a:apache:commons_io:2.21.0:*:*:*:*:*:*:*pkg:maven/commons-io/commons-io@2.21.0 0Highest127
commons-jexl-2.1.1.jarcpe:2.3:a:spirit-project:spirit:2.1.1:*:*:*:*:*:*:*pkg:maven/org.apache.commons/commons-jexl@2.1.1 0Low90
commons-jexl3-3.6.1.jarcpe:2.3:a:spirit-project:spirit:3.6.1:*:*:*:*:*:*:*pkg:maven/org.apache.commons/commons-jexl3@3.6.1 0Low102
commons-lang3-3.20.0.jarcpe:2.3:a:apache:commons_lang:3.20.0:*:*:*:*:*:*:*pkg:maven/org.apache.commons/commons-lang3@3.20.0 0Highest145
commons-logging-1.3.5.jarpkg:maven/commons-logging/commons-logging@1.3.5 0129
commons-math-1.2.jarpkg:maven/commons-math/commons-math@1.2 082
commons-pool-1.6.jarpkg:maven/commons-pool/commons-pool@1.6 075
commons-text-1.15.0.jarcpe:2.3:a:apache:commons_text:1.15.0:*:*:*:*:*:*:*pkg:maven/org.apache.commons/commons-text@1.15.0 0Highest73
commons-validator-1.10.1.jarpkg:maven/commons-validator/commons-validator@1.10.1 0130
commons-vfs2-2.10.0.jarcpe:2.3:a:apache:commons_vfs:2.10.0:*:*:*:*:*:*:*pkg:maven/org.apache.commons/commons-vfs2@2.10.0 0Highest39
content-type-2.3.jarpkg:maven/com.nimbusds/content-type@2.3 047
cron-parser-core-3.5.jarpkg:maven/net.redhogs.cronparser/cron-parser-core@3.5 024
csrfguard-4.1.4.jarcpe:2.3:a:owasp:csrfguard:4.1.4:*:*:*:*:*:*:*pkg:maven/org.owasp/csrfguard@4.1.4HIGH1Highest26
csrfguard-4.1.4.jar: csrfguard.js 00
csrfguard-jsp-tags-4.1.4.jarcpe:2.3:a:owasp:csrfguard:4.1.4:*:*:*:*:*:*:*pkg:maven/org.owasp/csrfguard-jsp-tags@4.1.4 0Highest26
dom4j-2.2.0.jarcpe:2.3:a:dom4j_project:dom4j:2.2.0:*:*:*:*:*:*:*pkg:maven/org.dom4j/dom4j@2.2.0 0Highest21
driver-1.57.0.jarcpe:2.3:a:microsoft:playwright:1.57.0:*:*:*:*:*:*:*pkg:maven/com.microsoft.playwright/driver@1.57.0 0Highest23
driver-bundle-1.57.0.jar: android.js 00
driver-bundle-1.57.0.jar: android.js 00
driver-bundle-1.57.0.jar: androidDispatcher.js 00
driver-bundle-1.57.0.jar: androidServerImpl.js 00
driver-bundle-1.57.0.jar: api.js 00
driver-bundle-1.57.0.jar: ariaSnapshot.js 00
driver-bundle-1.57.0.jar: artifact.js 00
driver-bundle-1.57.0.jar: artifact.js 00
driver-bundle-1.57.0.jar: artifactDispatcher.js 00
driver-bundle-1.57.0.jar: ascii.js 00
driver-bundle-1.57.0.jar: assert.js 00
driver-bundle-1.57.0.jar: backendAdb.js 00
driver-bundle-1.57.0.jar: bidiBrowser.js 00
driver-bundle-1.57.0.jar: bidiChromium.js 00
driver-bundle-1.57.0.jar: bidiCommands.d.js 00
driver-bundle-1.57.0.jar: bidiConnection.js 00
driver-bundle-1.57.0.jar: bidiDeserializer.js 00
driver-bundle-1.57.0.jar: bidiExecutionContext.js 00
driver-bundle-1.57.0.jar: bidiFirefox.js 00
driver-bundle-1.57.0.jar: bidiInput.js 00
driver-bundle-1.57.0.jar: bidiKeyboard.js 00
driver-bundle-1.57.0.jar: bidiNetworkManager.js 00
driver-bundle-1.57.0.jar: bidiOverCdp.js 00
driver-bundle-1.57.0.jar: bidiPage.js 00
driver-bundle-1.57.0.jar: bidiPdf.js 00
driver-bundle-1.57.0.jar: bidiProtocol.js 00
driver-bundle-1.57.0.jar: bidiProtocolCore.js 00
driver-bundle-1.57.0.jar: bidiProtocolPermissions.js 00
driver-bundle-1.57.0.jar: bidiSerializer.js 00
driver-bundle-1.57.0.jar: bindingsControllerSource.js 00
driver-bundle-1.57.0.jar: browser.js 00
driver-bundle-1.57.0.jar: browser.js 00
driver-bundle-1.57.0.jar: browserContext.js 00
driver-bundle-1.57.0.jar: browserContext.js 00
driver-bundle-1.57.0.jar: browserContextDispatcher.js 00
driver-bundle-1.57.0.jar: browserDispatcher.js 00
driver-bundle-1.57.0.jar: browserFetcher.js 00
driver-bundle-1.57.0.jar: browserServerImpl.js 00
driver-bundle-1.57.0.jar: browserType.js 00
driver-bundle-1.57.0.jar: browserType.js 00
driver-bundle-1.57.0.jar: browserTypeDispatcher.js 00
driver-bundle-1.57.0.jar: callLog.js 00
driver-bundle-1.57.0.jar: cdpSession.js 00
driver-bundle-1.57.0.jar: cdpSessionDispatcher.js 00
driver-bundle-1.57.0.jar: channelOwner.js 00
driver-bundle-1.57.0.jar: chat.js 00
driver-bundle-1.57.0.jar: chromium.js 00
driver-bundle-1.57.0.jar: chromiumSwitches.js 00
driver-bundle-1.57.0.jar: cli.js 00
driver-bundle-1.57.0.jar: clientHelper.js 00
driver-bundle-1.57.0.jar: clientInstrumentation.js 00
driver-bundle-1.57.0.jar: clientStackTrace.js 00
driver-bundle-1.57.0.jar: clock.js 00
driver-bundle-1.57.0.jar: clock.js 00
driver-bundle-1.57.0.jar: clockSource.js 00
driver-bundle-1.57.0.jar: codeMirrorModule-BoWUGj0J.js 00
driver-bundle-1.57.0.jar: codeMirrorModule-Bucv2d7q.js 00
driver-bundle-1.57.0.jar: colorUtils.js 00
driver-bundle-1.57.0.jar: colors.js 00
driver-bundle-1.57.0.jar: comparators.js 00
driver-bundle-1.57.0.jar: compare.js 00
driver-bundle-1.57.0.jar: connection.js 00
driver-bundle-1.57.0.jar: console.js 00
driver-bundle-1.57.0.jar: consoleMessage.js 00
driver-bundle-1.57.0.jar: cookieStore.js 00
driver-bundle-1.57.0.jar: coverage.js 00
driver-bundle-1.57.0.jar: crBrowser.js 00
driver-bundle-1.57.0.jar: crConnection.js 00
driver-bundle-1.57.0.jar: crCoverage.js 00
driver-bundle-1.57.0.jar: crDevTools.js 00
driver-bundle-1.57.0.jar: crDragDrop.js 00
driver-bundle-1.57.0.jar: crExecutionContext.js 00
driver-bundle-1.57.0.jar: crInput.js 00
driver-bundle-1.57.0.jar: crNetworkManager.js 00
driver-bundle-1.57.0.jar: crPage.js 00
driver-bundle-1.57.0.jar: crPdf.js 00
driver-bundle-1.57.0.jar: crProtocolHelper.js 00
driver-bundle-1.57.0.jar: crServiceWorker.js 00
driver-bundle-1.57.0.jar: crypto.js 00
driver-bundle-1.57.0.jar: csharp.js 00
driver-bundle-1.57.0.jar: cssParser.js 00
driver-bundle-1.57.0.jar: cssTokenizer.js 00
driver-bundle-1.57.0.jar: debug.js 00
driver-bundle-1.57.0.jar: debugController.js 00
driver-bundle-1.57.0.jar: debugControllerDispatcher.js 00
driver-bundle-1.57.0.jar: debugLogger.js 00
driver-bundle-1.57.0.jar: debugger.js 00
driver-bundle-1.57.0.jar: defaultFontFamilies.js 00
driver-bundle-1.57.0.jar: defaultSettingsView-BEpdCv1S.js 00
driver-bundle-1.57.0.jar: dependencies.js 00
driver-bundle-1.57.0.jar: deviceDescriptors.js 00
driver-bundle-1.57.0.jar: dialog.js 00
driver-bundle-1.57.0.jar: dialog.js 00
driver-bundle-1.57.0.jar: dialogDispatcher.js 00
driver-bundle-1.57.0.jar: dispatcher.js 00
driver-bundle-1.57.0.jar: dom.js 00
driver-bundle-1.57.0.jar: download.js 00
driver-bundle-1.57.0.jar: download.js 00
driver-bundle-1.57.0.jar: driver.js 00
driver-bundle-1.57.0.jar: electron.js 00
driver-bundle-1.57.0.jar: electron.js 00
driver-bundle-1.57.0.jar: electronDispatcher.js 00
driver-bundle-1.57.0.jar: elementHandle.js 00
driver-bundle-1.57.0.jar: elementHandlerDispatcher.js 00
driver-bundle-1.57.0.jar: env.js 00
driver-bundle-1.57.0.jar: errors.js 00
driver-bundle-1.57.0.jar: errors.js 00
driver-bundle-1.57.0.jar: eventEmitter.js 00
driver-bundle-1.57.0.jar: events.js 00
driver-bundle-1.57.0.jar: eventsHelper.js 00
driver-bundle-1.57.0.jar: expectUtils.js 00
driver-bundle-1.57.0.jar: fetch.js 00
driver-bundle-1.57.0.jar: fetch.js 00
driver-bundle-1.57.0.jar: ffBrowser.js 00
driver-bundle-1.57.0.jar: ffConnection.js 00
driver-bundle-1.57.0.jar: ffExecutionContext.js 00
driver-bundle-1.57.0.jar: ffInput.js 00
driver-bundle-1.57.0.jar: ffNetworkManager.js 00
driver-bundle-1.57.0.jar: ffPage.js 00
driver-bundle-1.57.0.jar: fileChooser.js 00
driver-bundle-1.57.0.jar: fileChooser.js 00
driver-bundle-1.57.0.jar: fileUploadUtils.js 00
driver-bundle-1.57.0.jar: fileUtils.js 00
driver-bundle-1.57.0.jar: fileUtils.js 00
driver-bundle-1.57.0.jar: firefox.js 00
driver-bundle-1.57.0.jar: firefoxPrefs.js 00
driver-bundle-1.57.0.jar: formData.js 00
driver-bundle-1.57.0.jar: frame.js 00
driver-bundle-1.57.0.jar: frameDispatcher.js 00
driver-bundle-1.57.0.jar: frameSelectors.js 00
driver-bundle-1.57.0.jar: frames.js 00
driver-bundle-1.57.0.jar: happyEyeballs.js 00
driver-bundle-1.57.0.jar: harBackend.js 00
driver-bundle-1.57.0.jar: harRecorder.js 00
driver-bundle-1.57.0.jar: harRouter.js 00
driver-bundle-1.57.0.jar: harTracer.js 00
driver-bundle-1.57.0.jar: headers.js 00
driver-bundle-1.57.0.jar: helper.js 00
driver-bundle-1.57.0.jar: hostPlatform.js 00
driver-bundle-1.57.0.jar: httpServer.js 00
driver-bundle-1.57.0.jar: imageChannel.js 00
driver-bundle-1.57.0.jar: imageUtils.js 00
driver-bundle-1.57.0.jar: inMemorySnapshotter.js 00
driver-bundle-1.57.0.jar: inProcessFactory.js 00
driver-bundle-1.57.0.jar: index-DJqDAOZp.js 00
driver-bundle-1.57.0.jar: index.BxQ34UMZ.js 00
driver-bundle-1.57.0.jar: index.js 00
driver-bundle-1.57.0.jar: index.js 00
driver-bundle-1.57.0.jar: index.js 00
driver-bundle-1.57.0.jar: index.js 00
driver-bundle-1.57.0.jar: injectedScriptSource.js 00
driver-bundle-1.57.0.jar: inprocess.js 00
driver-bundle-1.57.0.jar: input.js 00
driver-bundle-1.57.0.jar: input.js 00
driver-bundle-1.57.0.jar: instrumentation.js 00
driver-bundle-1.57.0.jar: java.js 00
driver-bundle-1.57.0.jar: javascript.js 00
driver-bundle-1.57.0.jar: javascript.js 00
driver-bundle-1.57.0.jar: jsHandle.js 00
driver-bundle-1.57.0.jar: jsHandleDispatcher.js 00
driver-bundle-1.57.0.jar: jsonPipe.js 00
driver-bundle-1.57.0.jar: jsonPipeDispatcher.js 00
driver-bundle-1.57.0.jar: jsonl.js 00
driver-bundle-1.57.0.jar: language.js 00
driver-bundle-1.57.0.jar: languages.js 00
driver-bundle-1.57.0.jar: launchApp.js 00
driver-bundle-1.57.0.jar: linuxUtils.js 00
driver-bundle-1.57.0.jar: loader.js 00
driver-bundle-1.57.0.jar: localUtils.js 00
driver-bundle-1.57.0.jar: localUtils.js 00
driver-bundle-1.57.0.jar: localUtilsDispatcher.js 00
driver-bundle-1.57.0.jar: locator.js 00
driver-bundle-1.57.0.jar: locatorGenerators.js 00
driver-bundle-1.57.0.jar: locatorParser.js 00
driver-bundle-1.57.0.jar: locatorUtils.js 00
driver-bundle-1.57.0.jar: macEditingCommands.js 00
driver-bundle-1.57.0.jar: manualPromise.js 00
driver-bundle-1.57.0.jar: mimeType.js 00
driver-bundle-1.57.0.jar: multimap.js 00
driver-bundle-1.57.0.jar: nativeDeps.js 00
driver-bundle-1.57.0.jar: network.js 00
driver-bundle-1.57.0.jar: network.js 00
driver-bundle-1.57.0.jar: network.js 00
driver-bundle-1.57.0.jar: networkDispatchers.js 00
driver-bundle-1.57.0.jar: nodePlatform.js 00
driver-bundle-1.57.0.jar: oopDownloadBrowserMain.js 00
driver-bundle-1.57.0.jar: outofprocess.js 00
driver-bundle-1.57.0.jar: package.json 00
driver-bundle-1.57.0.jar: page.js 00
driver-bundle-1.57.0.jar: page.js 00
driver-bundle-1.57.0.jar: pageDispatcher.js 00
driver-bundle-1.57.0.jar: pipeTransport.js 00
driver-bundle-1.57.0.jar: pipeTransport.js 00
driver-bundle-1.57.0.jar: pixelmatch.js 00
driver-bundle-1.57.0.jar: platform.js 00
driver-bundle-1.57.0.jar: playwright.js 00
driver-bundle-1.57.0.jar: playwright.js 00
driver-bundle-1.57.0.jar: playwrightConnection.js 00
driver-bundle-1.57.0.jar: playwrightDispatcher.js 00
driver-bundle-1.57.0.jar: playwrightServer.js 00
driver-bundle-1.57.0.jar: pollingRecorderSource.js 00
driver-bundle-1.57.0.jar: processLauncher.js 00
driver-bundle-1.57.0.jar: profiler.js 00
driver-bundle-1.57.0.jar: program.js 00
driver-bundle-1.57.0.jar: programWithTestStub.js 00
driver-bundle-1.57.0.jar: progress.js 00
driver-bundle-1.57.0.jar: protocol.d.js 00
driver-bundle-1.57.0.jar: protocolError.js 00
driver-bundle-1.57.0.jar: protocolFormatter.js 00
driver-bundle-1.57.0.jar: protocolMetainfo.js 00
driver-bundle-1.57.0.jar: python.js 00
driver-bundle-1.57.0.jar: recorder.js 00
driver-bundle-1.57.0.jar: recorderApp.js 00
driver-bundle-1.57.0.jar: recorderRunner.js 00
driver-bundle-1.57.0.jar: recorderSignalProcessor.js 00
driver-bundle-1.57.0.jar: recorderUtils.js 00
driver-bundle-1.57.0.jar: rtti.js 00
driver-bundle-1.57.0.jar: screenshotter.js 00
driver-bundle-1.57.0.jar: selectorParser.js 00
driver-bundle-1.57.0.jar: selectors.js 00
driver-bundle-1.57.0.jar: selectors.js 00
driver-bundle-1.57.0.jar: semaphore.js 00
driver-bundle-1.57.0.jar: serializers.js 00
driver-bundle-1.57.0.jar: snapshotter.js 00
driver-bundle-1.57.0.jar: snapshotterInjected.js 00
driver-bundle-1.57.0.jar: socksClientCertificatesInterceptor.js 00
driver-bundle-1.57.0.jar: socksInterceptor.js 00
driver-bundle-1.57.0.jar: socksProxy.js 00
driver-bundle-1.57.0.jar: spawnAsync.js 00
driver-bundle-1.57.0.jar: stackTrace.js 00
driver-bundle-1.57.0.jar: stats.js 00
driver-bundle-1.57.0.jar: storageScriptSource.js 00
driver-bundle-1.57.0.jar: stream.js 00
driver-bundle-1.57.0.jar: streamDispatcher.js 00
driver-bundle-1.57.0.jar: stringUtils.js 00
driver-bundle-1.57.0.jar: sw.bundle.js 00
driver-bundle-1.57.0.jar: task.js 00
driver-bundle-1.57.0.jar: throttledFile.js 00
driver-bundle-1.57.0.jar: time.js 00
driver-bundle-1.57.0.jar: timeoutRunner.js 00
driver-bundle-1.57.0.jar: timeoutSettings.js 00
driver-bundle-1.57.0.jar: traceUtils.js 00
driver-bundle-1.57.0.jar: traceViewer.js 00
driver-bundle-1.57.0.jar: tracing.js 00
driver-bundle-1.57.0.jar: tracing.js 00
driver-bundle-1.57.0.jar: tracingDispatcher.js 00
driver-bundle-1.57.0.jar: transport.js 00
driver-bundle-1.57.0.jar: types.js 00
driver-bundle-1.57.0.jar: types.js 00
driver-bundle-1.57.0.jar: uiMode.BWTwXl41.js 00
driver-bundle-1.57.0.jar: urlMatch.js 00
driver-bundle-1.57.0.jar: usKeyboardLayout.js 00
driver-bundle-1.57.0.jar: userAgent.js 00
driver-bundle-1.57.0.jar: utilityScriptSerializers.js 00
driver-bundle-1.57.0.jar: utilityScriptSource.js 00
driver-bundle-1.57.0.jar: utils.js 00
driver-bundle-1.57.0.jar: utilsBundle.js 00
driver-bundle-1.57.0.jar: validator.js 00
driver-bundle-1.57.0.jar: validatorPrimitives.js 00
driver-bundle-1.57.0.jar: video.js 00
driver-bundle-1.57.0.jar: videoRecorder.js 00
driver-bundle-1.57.0.jar: waiter.js 00
driver-bundle-1.57.0.jar: webError.js 00
driver-bundle-1.57.0.jar: webSocket.js 00
driver-bundle-1.57.0.jar: webSocketMockSource.js 00
driver-bundle-1.57.0.jar: webSocketRouteDispatcher.js 00
driver-bundle-1.57.0.jar: webkit.js 00
driver-bundle-1.57.0.jar: wkBrowser.js 00
driver-bundle-1.57.0.jar: wkConnection.js 00
driver-bundle-1.57.0.jar: wkExecutionContext.js 00
driver-bundle-1.57.0.jar: wkInput.js 00
driver-bundle-1.57.0.jar: wkInterceptableRequest.js 00
driver-bundle-1.57.0.jar: wkPage.js 00
driver-bundle-1.57.0.jar: wkProvisionalPage.js 00
driver-bundle-1.57.0.jar: wkWorkers.js 00
driver-bundle-1.57.0.jar: worker.js 00
driver-bundle-1.57.0.jar: writableStream.js 00
driver-bundle-1.57.0.jar: writableStreamDispatcher.js 00
driver-bundle-1.57.0.jar: wsServer.js 00
driver-bundle-1.57.0.jar: xtermModule-CsJ4vdCR.js 00
driver-bundle-1.57.0.jar: zipBundle.js 00
driver-bundle-1.57.0.jar: zipBundleImpl.js 00
driver-bundle-1.57.0.jar: zipFile.js 00
driver-bundle-1.57.0.jar: zones.js 00
edu.internet2.middleware.grouper:grouper:7.0.0-SNAPSHOTcpe:2.3:a:internet2:grouper:7.0.0:snapshot:*:*:*:*:*:*pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT 0Highest6
edu.internet2.middleware.grouper:grouperClient:7.0.0-SNAPSHOTcpe:2.3:a:internet2:grouper:7.0.0:snapshot:*:*:*:*:*:*pkg:maven/edu.internet2.middleware.grouper/grouperClient@7.0.0-SNAPSHOT 0Highest6
ehcache-core-2.6.11.jarpkg:maven/net.sf.ehcache/ehcache-core@2.6.11 022
ehcache-core-2.6.11.jar: sizeof-agent.jarpkg:maven/net.sf.ehcache/sizeof-agent@1.0.1 028
error_prone_annotations-2.41.0.jarpkg:maven/com.google.errorprone/error_prone_annotations@2.41.0 029
flexmark-0.64.8.jarpkg:maven/com.vladsch.flexmark/flexmark@0.64.8 023
flexmark-ext-emoji-0.64.8.jarpkg:maven/com.vladsch.flexmark/flexmark-ext-emoji@0.64.8 023
flexmark-ext-gfm-strikethrough-0.64.8.jarpkg:maven/com.vladsch.flexmark/flexmark-ext-gfm-strikethrough@0.64.8 023
flexmark-ext-ins-0.64.8.jarpkg:maven/com.vladsch.flexmark/flexmark-ext-ins@0.64.8 023
flexmark-ext-superscript-0.64.8.jarpkg:maven/com.vladsch.flexmark/flexmark-ext-superscript@0.64.8 023
flexmark-ext-tables-0.64.8.jarpkg:maven/com.vladsch.flexmark/flexmark-ext-tables@0.64.8 023
flexmark-ext-wikilink-0.64.8.jarcpe:2.3:a:links:links:0.64.8:*:*:*:*:*:*:*pkg:maven/com.vladsch.flexmark/flexmark-ext-wikilink@0.64.8 0Low23
flexmark-html2md-converter-0.64.8.jarpkg:maven/com.vladsch.flexmark/flexmark-html2md-converter@0.64.8 023
flexmark-jira-converter-0.64.8.jarpkg:maven/com.vladsch.flexmark/flexmark-jira-converter@0.64.8 023
flexmark-util-0.64.8.jarpkg:maven/com.vladsch.flexmark/flexmark-util@0.64.8 015
flexmark-util-ast-0.64.8.jarpkg:maven/com.vladsch.flexmark/flexmark-util-ast@0.64.8 023
flexmark-util-builder-0.64.8.jarpkg:maven/com.vladsch.flexmark/flexmark-util-builder@0.64.8 023
flexmark-util-collection-0.64.8.jarpkg:maven/com.vladsch.flexmark/flexmark-util-collection@0.64.8 023
flexmark-util-data-0.64.8.jarpkg:maven/com.vladsch.flexmark/flexmark-util-data@0.64.8 023
flexmark-util-dependency-0.64.8.jarpkg:maven/com.vladsch.flexmark/flexmark-util-dependency@0.64.8 023
flexmark-util-format-0.64.8.jarpkg:maven/com.vladsch.flexmark/flexmark-util-format@0.64.8 023
flexmark-util-html-0.64.8.jarpkg:maven/com.vladsch.flexmark/flexmark-util-html@0.64.8 023
flexmark-util-misc-0.64.8.jarpkg:maven/com.vladsch.flexmark/flexmark-util-misc@0.64.8 023
flexmark-util-options-0.64.8.jarpkg:maven/com.vladsch.flexmark/flexmark-util-options@0.64.8 023
flexmark-util-sequence-0.64.8.jarpkg:maven/com.vladsch.flexmark/flexmark-util-sequence@0.64.8 023
flexmark-util-visitor-0.64.8.jarpkg:maven/com.vladsch.flexmark/flexmark-util-visitor@0.64.8 023
geronimo-jms_2.0_spec-1.0-alpha-2.jarpkg:maven/org.apache.geronimo.specs/geronimo-jms_2.0_spec@1.0-alpha-2 030
groovy-2.5.23.jarcpe:2.3:a:apache:groovy:2.5.23:*:*:*:*:*:*:*pkg:maven/org.codehaus.groovy/groovy@2.5.23 0Highest291
groovy-xml-2.5.23.jarcpe:2.3:a:apache:groovy:2.5.23:*:*:*:*:*:*:*pkg:maven/org.codehaus.groovy/groovy-xml@2.5.23 0High287
gson-2.13.2.jarcpe:2.3:a:google:gson:2.13.2:*:*:*:*:*:*:*pkg:maven/com.google.code.gson/gson@2.13.2 0Highest31
hibernate-c3p0-5.6.15.Final.jarcpe:2.3:a:hibernate:hibernate_orm:5.6.15:*:*:*:*:*:*:*pkg:maven/org.hibernate/hibernate-c3p0@5.6.15.Final 0Low46
hibernate-commons-annotations-5.1.2.Final.jarpkg:maven/org.hibernate.common/hibernate-commons-annotations@5.1.2.Final 044
hibernate-core-5.6.15.Final.jarcpe:2.3:a:hibernate:hibernate_orm:5.6.15:*:*:*:*:*:*:*pkg:maven/org.hibernate/hibernate-core@5.6.15.FinalHIGH1Low44
httpclient-4.5.14.jarcpe:2.3:a:apache:httpclient:4.5.14:*:*:*:*:*:*:*pkg:maven/org.apache.httpcomponents/httpclient@4.5.14 0Highest32
httpcore-4.4.16.jarcpe:2.3:a:apache:httpcomponents_core:4.4.16:*:*:*:*:*:*:*pkg:maven/org.apache.httpcomponents/httpcore@4.4.16 0Highest32
httpmime-4.5.14.jarpkg:maven/org.apache.httpcomponents/httpmime@4.5.14 030
istack-commons-runtime-3.0.7.jarpkg:maven/com.sun.istack/istack-commons-runtime@3.0.7 032
jackson-annotations-2.22.jarcpe:2.3:a:fasterxml:jackson-core:2.22:*:*:*:*:*:*:*
cpe:2.3:a:fasterxml:jackson-modules-java8:2.22:*:*:*:*:*:*:*
pkg:maven/com.fasterxml.jackson.core/jackson-annotations@2.22 0Highest36
jackson-core-2.22.1.jarcpe:2.3:a:fasterxml:jackson-core:2.22.1:*:*:*:*:*:*:*
cpe:2.3:a:fasterxml:jackson-modules-java8:2.22.1:*:*:*:*:*:*:*
pkg:maven/com.fasterxml.jackson.core/jackson-core@2.22.1 0Highest47
jackson-databind-2.22.1.jarcpe:2.3:a:fasterxml:jackson-core:2.22.1:*:*:*:*:*:*:*
cpe:2.3:a:fasterxml:jackson-databind:2.22.1:*:*:*:*:*:*:*
cpe:2.3:a:fasterxml:jackson-modules-java8:2.22.1:*:*:*:*:*:*:*
pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.22.1 0Highest41
jackson-dataformat-cbor-2.17.2.jarcpe:2.3:a:fasterxml:jackson-dataformats-binary:2.17.2:*:*:*:*:*:*:*pkg:maven/com.fasterxml.jackson.dataformat/jackson-dataformat-cbor@2.17.2 0Low39
jakarta.activation-api-2.1.4.jarpkg:maven/jakarta.activation/jakarta.activation-api@2.1.4 045
jakarta.mail-api-2.1.5.jarcpe:2.3:a:eclipse:jakarta_mail:2.1.5:*:*:*:*:*:*:*pkg:maven/jakarta.mail/jakarta.mail-api@2.1.5 0High36
jakarta.xml.bind-api-4.0.4.jarpkg:maven/jakarta.xml.bind/jakarta.xml.bind-api@4.0.4 031
jandex-2.4.2.Final.jarpkg:maven/org.jboss/jandex@2.4.2.Final 042
java-ipv6-0.17.jarpkg:maven/com.googlecode.java-ipv6/java-ipv6@0.17 020
java-jwt-3.19.4.jarpkg:maven/com.auth0/java-jwt@3.19.4 039
javassist-3.30.2-GA.jarpkg:maven/org.javassist/javassist@3.30.2-GA 059
javax.activation-api-1.2.0.jarpkg:maven/javax.activation/javax.activation-api@1.2.0 039
javax.persistence-api-2.2.jarpkg:maven/javax.persistence/javax.persistence-api@2.2 031
javax.servlet-api-3.1.0.jarcpe:2.3:a:oracle:java_se:3.1.0:*:*:*:*:*:*:*pkg:maven/javax.servlet/javax.servlet-api@3.1.0 0Medium49
javax.servlet.jsp-api-2.3.3.jarcpe:2.3:a:oracle:java_se:2.3.3:*:*:*:*:*:*:*
cpe:2.3:a:oracle:jsp:2.3.3:*:*:*:*:*:*:*
pkg:maven/javax.servlet.jsp/javax.servlet.jsp-api@2.3.3 0High46
javax.servlet.jsp.jstl-api-1.2.2.jarcpe:2.3:a:oracle:jsp:1.2.2:*:*:*:*:*:*:*pkg:maven/javax.servlet.jsp.jstl/javax.servlet.jsp.jstl-api@1.2.2 0High49
jaxb-api-2.3.1.jarpkg:maven/javax.xml.bind/jaxb-api@2.3.1 035
jaxb-runtime-2.3.1.jarpkg:maven/org.glassfish.jaxb/jaxb-runtime@2.3.1 032
jboss-logging-3.6.1.Final.jarpkg:maven/org.jboss.logging/jboss-logging@3.6.1.Final 043
jboss-transaction-api_1.2_spec-1.1.1.Final.jarpkg:maven/org.jboss.spec.javax.transaction/jboss-transaction-api_1.2_spec@1.1.1.Final 039
jcip-annotations-1.0-1.jarpkg:maven/com.github.stephenc.jcip/jcip-annotations@1.0-1 025
jetty-6.1.26.jarcpe:2.3:a:jetty:jetty:6.1.26:*:*:*:*:*:*:*
cpe:2.3:a:mortbay:jetty:6.1.26:*:*:*:*:*:*:*
cpe:2.3:a:mortbay_jetty:jetty:6.1.26:*:*:*:*:*:*:*
pkg:maven/org.mortbay.jetty/jetty@6.1.26MEDIUM2Highest34
jline-2.14.6.jarcpe:2.3:a:jline:jline:2.14.6:*:*:*:*:*:*:*pkg:maven/jline/jline@2.14.6MEDIUM1Highest35
jmespath-java-1.12.796.jarcpe:2.3:a:amazon:aws-sdk-java:1.12.796:*:*:*:*:*:*:*pkg:maven/com.amazonaws/jmespath-java@1.12.796 0Low28
joda-time-2.14.0.jarpkg:maven/joda-time/joda-time@2.14.0 047
jsch-0.2.25.jarcpe:2.3:a:jcraft:jsch:0.2.25:*:*:*:*:*:*:*pkg:maven/com.github.mwiede/jsch@0.2.25 0Highest57
json-smart-2.5.2.jarcpe:2.3:a:json-smart_project:json-smart:2.5.2:*:*:*:*:*:*:*
cpe:2.3:a:json-smart_project:json-smart-v2:2.5.2:*:*:*:*:*:*:*
pkg:maven/net.minidev/json-smart@2.5.2 0Highest51
jsoup-1.21.1.jarcpe:2.3:a:jsoup:jsoup:1.21.1:*:*:*:*:*:*:*pkg:maven/org.jsoup/jsoup@1.21.1 0Highest44
jta-1.1.jarpkg:maven/javax.transaction/jta@1.1 022
lang-tag-1.7.jarpkg:maven/com.nimbusds/lang-tag@1.7 047
ldaptive-2.4.2.jarcpe:2.3:a:ldaptive:ldaptive:2.4.2:*:*:*:*:*:*:*pkg:maven/org.ldaptive/ldaptive@2.4.2 0Highest23
log4j-core-2.26.0.jarcpe:2.3:a:apache:log4j:2.26.0:*:*:*:*:*:*:*pkg:maven/org.apache.logging.log4j/log4j-core@2.26.0MEDIUM1Highest42
log4j-slf4j-impl-2.26.0.jarpkg:maven/org.apache.logging.log4j/log4j-slf4j-impl@2.26.0 038
lucene-analysis-common-9.12.1.jarpkg:maven/org.apache.lucene/lucene-analysis-common@9.12.1 027
lucene-core-9.12.1.jarpkg:maven/org.apache.lucene/lucene-core@9.12.1 030
lucene-facet-9.12.1.jarpkg:maven/org.apache.lucene/lucene-facet@9.12.1 027
lucene-queries-9.12.1.jarpkg:maven/org.apache.lucene/lucene-queries@9.12.1 027
lucene-queryparser-9.12.1.jarpkg:maven/org.apache.lucene/lucene-queryparser@9.12.1 027
lucene-sandbox-9.12.1.jarpkg:maven/org.apache.lucene/lucene-sandbox@9.12.1 028
mchange-commons-java-0.4.0.jarcpe:2.3:a:mchange:mchange_commons_java:0.4.0:*:*:*:*:*:*:*pkg:maven/com.mchange/mchange-commons-java@0.4.0HIGH1Highest31
mxparser-1.2.2.jarpkg:maven/io.github.x-stream/mxparser@1.2.2 058
mysql-connector-j-9.5.0.jarcpe:2.3:a:oracle:mysql_connector\/j:9.5.0:*:*:*:*:*:*:*pkg:maven/com.mysql/mysql-connector-j@9.5.0 0Highest52
netty-codec-4.2.7.Final.jarcpe:2.3:a:netty:netty:4.2.7:*:*:*:*:*:*:*pkg:maven/io.netty/netty-codec@4.2.7.FinalCRITICAL48Highest31
netty-codec-compression-4.2.7.Final.jarcpe:2.3:a:netty:netty:4.2.7:*:*:*:*:*:*:*pkg:maven/io.netty/netty-codec-compression@4.2.7.FinalCRITICAL49Highest37
netty-codec-http-4.1.72.Final.jarcpe:2.3:a:netty:netty:4.1.72:*:*:*:*:*:*:*pkg:maven/io.netty/netty-codec-http@4.1.72.FinalCRITICAL*55Highest32
netty-codec-protobuf-4.2.7.Final.jarcpe:2.3:a:netty:netty:4.2.7:*:*:*:*:*:*:*
cpe:2.3:a:protobuf:protobuf:4.2.7:*:*:*:*:*:*:*
pkg:maven/io.netty/netty-codec-protobuf@4.2.7.FinalCRITICAL48Highest37
netty-common-4.1.72.Final.jar (shaded: org.jctools:jctools-core:3.1.0)pkg:maven/org.jctools/jctools-core@3.1.0 09
netty-transport-4.1.72.Final.jarcpe:2.3:a:netty:netty:4.1.72:*:*:*:*:*:*:*pkg:maven/io.netty/netty-transport@4.1.72.FinalCRITICAL*52Highest30
netty-transport-classes-epoll-4.1.123.Final.jarcpe:2.3:a:netty:netty:4.1.123:*:*:*:*:*:*:*pkg:maven/io.netty/netty-transport-classes-epoll@4.1.123.FinalCRITICAL45Highest36
nimbus-jose-jwt-10.6.jar (shaded: com.google.code.gson:gson:2.13.1)cpe:2.3:a:google:gson:2.13.1:*:*:*:*:*:*:*pkg:maven/com.google.code.gson/gson@2.13.1 0Highest9
nimbus-jose-jwt-10.6.jarcpe:2.3:a:connect2id:nimbus_jose\+jwt:10.6:*:*:*:*:*:*:*pkg:maven/com.nimbusds/nimbus-jose-jwt@10.6 0Highest50
oauth2-oidc-sdk-11.30.1.jarpkg:maven/com.nimbusds/oauth2-oidc-sdk@11.30.1 057
opentest4j-1.3.0.jarpkg:maven/org.opentest4j/opentest4j@1.3.0 060
org.apache.felix.framework-7.0.5.jarpkg:maven/org.apache.felix/org.apache.felix.framework@7.0.5 037
oro-2.0.8.jarpkg:maven/oro/oro@2.0.8 016
picocli-4.3.2.jarpkg:maven/info.picocli/picocli@4.3.2 034
playwright-1.57.0.jarcpe:2.3:a:microsoft:playwright:1.57.0:*:*:*:*:*:*:*pkg:maven/com.microsoft.playwright/playwright@1.57.0 0Highest23
postgresql-42.7.11.jarcpe:2.3:a:postgresql:postgresql_jdbc_driver:42.7.11:*:*:*:*:*:*:*pkg:maven/org.postgresql/postgresql@42.7.11HIGH1Low76
protobuf-java-4.31.1.jarcpe:2.3:a:google:protobuf:4.31.1:*:*:*:*:*:*:*
cpe:2.3:a:google:protobuf-java:4.31.1:*:*:*:*:*:*:*
cpe:2.3:a:protobuf:protobuf:4.31.1:*:*:*:*:*:*:*
pkg:maven/com.google.protobuf/protobuf-java@4.31.1HIGH1Highest25
proton-j-0.33.10.jarcpe:2.3:a:apache:qpid:0.33.10:*:*:*:*:*:*:*
cpe:2.3:a:apache:qpid_proton:0.33.10:*:*:*:*:*:*:*
cpe:2.3:a:apache:qpid_proton-j:0.33.10:*:*:*:*:*:*:*
cpe:2.3:a:proton_project:proton:0.33.10:*:*:*:*:*:*:*
pkg:maven/org.apache.qpid/proton-j@0.33.10 0Highest28
qpid-jms-client-0.61.0.jarcpe:2.3:a:apache:qpid:0.61.0:*:*:*:*:*:*:*pkg:maven/org.apache.qpid/qpid-jms-client@0.61.0 0Highest25
quartz-2.5.2.jarcpe:2.3:a:softwareag:quartz:2.5.2:*:*:*:*:*:*:*pkg:maven/org.quartz-scheduler/quartz@2.5.2 0Highest37
slf4j-api-1.7.36.jarpkg:maven/org.slf4j/slf4j-api@1.7.36 029
smack-3.1.0.jarpkg:maven/jivesoftware/smack@3.1.0MEDIUM222
standard-1.1.2.jarcpe:2.3:a:apache:standard_taglibs:1.1.2:*:*:*:*:*:*:*pkg:maven/taglibs/standard@1.1.2HIGH1Highest23
stax-ex-1.8.jarpkg:maven/org.jvnet.staxex/stax-ex@1.8 046
txw2-2.3.1.jarpkg:maven/org.glassfish.jaxb/txw2@2.3.1 034
xercesImpl-2.12.2.jarcpe:2.3:a:apache:xerces-j:2.12.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:xerces2_java:2.12.2:*:*:*:*:*:*:*
pkg:maven/xerces/xercesImpl@2.12.2CRITICAL2Low84
xmlpull-1.1.3.1.jarpkg:maven/xmlpull/xmlpull@1.1.3.1 018
xstream-1.4.21.jarcpe:2.3:a:xstream:xstream:1.4.21:*:*:*:*:*:*:*pkg:maven/com.thoughtworks.xstream/xstream@1.4.21 0Highest55

* indicates the dependency has a known exploited vulnerability

Dependencies (vulnerable)

FastInfoset-1.2.15.jar

Description:

Open Source implementation of the Fast Infoset Standard for Binary XML (http://www.itu.int/ITU-T/asn1/).

License:

http://www.opensource.org/licenses/apache2.0.php
File Path: /home/grprdist/.m2/repository/com/sun/xml/fastinfoset/FastInfoset/1.2.15/FastInfoset-1.2.15.jar
MD5: 57f3894ad7e069ae740b277d92d10fa0
SHA1: bb7b7ec0379982b97c62cd17465cb6d9155f68e8
SHA256:785861db11ca1bd0d1956682b974ad73eb19cd3e01a4b3fa82d62eca97210aec
Referenced In Project/Scope: Grouper UI:compile
FastInfoset-1.2.15.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

accessors-smart-2.5.2.jar

Description:

Java reflect give poor performance on getter setter an constructor calls, accessors-smart use ASM to speed up those calls.

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/net/minidev/accessors-smart/2.5.2/accessors-smart-2.5.2.jar
MD5: 24191e0bb215c72902e89f46dde839e1
SHA1: ce16fd235cfee48e67eda33e684423bba09f7d07
SHA256:9b8a7bc43861d6156c021166d941fb7dddbe4463e2fa5ee88077e4b01452a836
Referenced In Project/Scope: Grouper UI:compile
accessors-smart-2.5.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

amqp-client-5.28.0.jar

Description:

The RabbitMQ Java client library allows Java applications to interface with RabbitMQ.

License:

AL 2.0: https://www.apache.org/licenses/LICENSE-2.0.html
GPL v2: https://www.gnu.org/licenses/gpl-2.0.txt
MPL 2.0: https://www.mozilla.org/en-US/MPL/2.0/
File Path: /home/grprdist/.m2/repository/com/rabbitmq/amqp-client/5.28.0/amqp-client-5.28.0.jar
MD5: 71dca1f29728e6ff90b764bdcaaaefcd
SHA1: abb8ea0beb5710ceb773a73e9e4604d8482dab91
SHA256:1bf99de72926694452454bd496e0c8eec52d5d0901a96dc5fa0c5e946d0193eb
Referenced In Project/Scope: Grouper UI:compile
amqp-client-5.28.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

CVE-2026-61634 (OSSINDEX)  

amqp-client - frame size limit bypass causes memory exhaustion

Sonatype's research suggests that this CVE's details differ from those defined at NVD. See https://guide.sonatype.com/vulnerability/CVE-2026-61634 for details
CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv2:
  • Base Score: MEDIUM (6.300000190734863)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

References:

Vulnerable Software & Versions (OSSINDEX):

  • cpe:2.3:a:com.rabbitmq:amqp-client:5.28.0:*:*:*:*:*:*:*

angus-activation-2.0.3.jar

Description:

 Implementation

License:

http://www.eclipse.org/org/documents/edl-v10.php
File Path: /home/grprdist/.m2/repository/org/eclipse/angus/angus-activation/2.0.3/angus-activation-2.0.3.jar
MD5: ad20392145690b36b4f950fe31a31a2a
SHA1: 7f80607ea5014fef0b1779e6c33d63a88a45a563
SHA256:a6bd35c538cf90fff941ad6258c40c08fca0b5c9c3f536c657114f27ce0527a7
Referenced In Project/Scope: Grouper UI:runtime
angus-activation-2.0.3.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

angus-mail-2.0.5.jar (shaded: org.eclipse.angus:angus-core:2.0.5)

File Path: /home/grprdist/.m2/repository/org/eclipse/angus/angus-mail/2.0.5/angus-mail-2.0.5.jar/META-INF/maven/org.eclipse.angus/angus-core/pom.xml
MD5: 102fa937d3897ac6eb838ff3a716bc80
SHA1: 11d1302ad859e7dda8e897ffa278a2135d0d3c7e
SHA256:162bec7f0c7a2c3d461a42ca576e139b80628798f97f274b7dd5759226fc47c1
Referenced In Project/Scope: Grouper UI:compile

Identifiers

angus-mail-2.0.5.jar (shaded: org.eclipse.angus:logging-mailhandler:2.0.5)

File Path: /home/grprdist/.m2/repository/org/eclipse/angus/angus-mail/2.0.5/angus-mail-2.0.5.jar/META-INF/maven/org.eclipse.angus/logging-mailhandler/pom.xml
MD5: d4925a2ff344f2fab35fdf31f4813b43
SHA1: 53aac2712cc43a3aed66f65536fd91709056aef1
SHA256:869577c24e1abb117bd9cf7dc9228c2643839b75087bfc5d6fed0d328ed9d1f7
Referenced In Project/Scope: Grouper UI:compile

Identifiers

angus-mail-2.0.5.jar

Description:

Angus Mail Provider

License:

http://www.eclipse.org/legal/epl-2.0, https://www.gnu.org/software/classpath/license.html, http://www.eclipse.org/org/documents/edl-v10.php
File Path: /home/grprdist/.m2/repository/org/eclipse/angus/angus-mail/2.0.5/angus-mail-2.0.5.jar
MD5: e965a2653568c0138457b4c6fc9e5d77
SHA1: 427f6d52ec0782f7efaca0c0732042e347a6cb4f
SHA256:b4d8c30d35f455def6c7a05fe595a1e62ea2b80cac3efec1e9ccf4118b23168a
Referenced In Project/Scope: Grouper UI:compile
angus-mail-2.0.5.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

animal-sniffer-annotations-1.9.jar

File Path: /home/grprdist/.m2/repository/org/codehaus/mojo/animal-sniffer-annotations/1.9/animal-sniffer-annotations-1.9.jar
MD5: 41f47a4c81b5a9f76bc7f12af69e4fbe
SHA1: c29299253a087898aaff7f4eac57effa46b1910a
SHA256:cd96feeb47f34b2559704715db7b179a03a3721f9dc4092c345c718e29b42de4
Referenced In Project/Scope: Grouper UI:compile
animal-sniffer-annotations-1.9.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

annotations-24.0.1.jar

Description:

A set of annotations used for code inspection support and code documentation.

License:

The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/org/jetbrains/annotations/24.0.1/annotations-24.0.1.jar
MD5: 63ebd6140ac340babaf89a754c359596
SHA1: 13c5c75c4206580aa4d683bffee658caae6c9f43
SHA256:61666dbce7e42e6c85b43c04fcfb8293a21dcb55b3c80e869270ce42c01a6b35
Referenced In Project/Scope: Grouper UI:compile
annotations-24.0.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

ant-1.10.15.jar

File Path: /home/grprdist/.m2/repository/org/apache/ant/ant/1.10.15/ant-1.10.15.jar
MD5: 688b6e5ca5900863c26af4fe4ee7e924
SHA1: da854f5503ee061a5a3b2cfcbe98ee27aa4a5ef9
SHA256:763acda4a69588c9ea8817a952851ff0c2fc4bffa1d081c2565dc407f29d5794
Referenced In Project/Scope: Grouper UI:compile
ant-1.10.15.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

antlr-2.7.7.jar

Description:

    A framework for constructing recognizers, compilers,
    and translators from grammatical descriptions containing
    Java, C#, C++, or Python actions.
  

License:

BSD License: http://www.antlr.org/license.html
File Path: /home/grprdist/.m2/repository/antlr/antlr/2.7.7/antlr-2.7.7.jar
MD5: f8f1352c52a4c6a500b597596501fc64
SHA1: 83cd2cd674a217ade95a4bb83a8a14f351f48bd0
SHA256:88fbda4b912596b9f56e8e12e580cc954bacfb51776ecfddd3e18fc1cf56dc4c
Referenced In Project/Scope: Grouper UI:compile
antlr-2.7.7.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

asm-7.1.jar

Description:

ASM, a very small and fast Java bytecode manipulation framework

License:

BSD: http://asm.ow2.org/license.html
File Path: /home/grprdist/.m2/repository/org/ow2/asm/asm/7.1/asm-7.1.jar
MD5: 04fc92647ce25b41121683674a50dfdf
SHA1: fa29aa438674ff19d5e1386d2c3527a0267f291e
SHA256:4ab2fa2b6d2cc9ccb1eaa05ea329c407b47b13ed2915f62f8c4b8cc96258d4de
Referenced In Project/Scope: Grouper UI:compile
asm-7.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

aws-java-sdk-core-1.12.796.jar

Description:

The AWS SDK for Java - Core module holds the classes that are used by the individual service clients to interact with Amazon Web Services. Users need to depend on aws-java-sdk artifact for accessing individual client classes.

File Path: /home/grprdist/.m2/repository/com/amazonaws/aws-java-sdk-core/1.12.796/aws-java-sdk-core-1.12.796.jar
MD5: 0d64c2129ef85a96a02245583baa365e
SHA1: 7b7837a39232f910aae66dfd4606ad3a3e2f6c21
SHA256:414c83d8d65528c495b0f442278bc439b4d920c64fd31b22127214c053452a40
Referenced In Project/Scope: Grouper UI:compile
aws-java-sdk-core-1.12.796.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

bcpkix-jdk18on-1.84.jar

Description:

The Bouncy Castle Java APIs for CMS, PKCS, EAC, TSP, CMP, CRMF, OCSP, and certificate generation. This jar contains  APIs for Java 1.8 and later. The APIs are designed primarily to be used in conjunction with the BC Java provider but may also be used with other providers providing cryptographic services.

License:

Bouncy Castle Licence: https://www.bouncycastle.org/licence.html
File Path: /home/grprdist/.m2/repository/org/bouncycastle/bcpkix-jdk18on/1.84/bcpkix-jdk18on-1.84.jar
MD5: 49dec53975e3a6d23d7e3979551ce3c3
SHA1: dab889a3259e27caec6e6c2f3bde94af036b2fcc
SHA256:c87f16ed9e5ec61bc94151e9f3646ac44e50cd448121ce84367fa4b7ec7ec1bb
Referenced In Project/Scope: Grouper UI:compile
bcpkix-jdk18on-1.84.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

CVE-2026-12802 (OSSINDEX)  

In Bouncy Castle for Java before 1.85, CMS AuthEnvelopedData fails to enforce tag-length on decryption. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
CWE-354 Improper Validation of Integrity Check Value

CVSSv2:
  • Base Score: HIGH (8.699999809265137)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

References:

Vulnerable Software & Versions (OSSINDEX):

  • cpe:2.3:a:org.bouncycastle:bcpkix-jdk18on:1.84:*:*:*:*:*:*:*

CVE-2026-59639 (OSSINDEX)  

In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
CWE-347 Improper Verification of Cryptographic Signature

CVSSv2:
  • Base Score: HIGH (8.699999809265137)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

References:

Vulnerable Software & Versions (OSSINDEX):

  • cpe:2.3:a:org.bouncycastle:bcpkix-jdk18on:1.84:*:*:*:*:*:*:*

CVE-2026-59642 (OSSINDEX)  

In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
CWE-354 Improper Validation of Integrity Check Value

CVSSv2:
  • Base Score: HIGH (8.699999809265137)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

References:

Vulnerable Software & Versions (OSSINDEX):

  • cpe:2.3:a:org.bouncycastle:bcpkix-jdk18on:1.84:*:*:*:*:*:*:*

CVE-2026-59647 (OSSINDEX)  

In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours unbounded iteration count. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv2:
  • Base Score: MEDIUM (6.900000095367432)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

References:

Vulnerable Software & Versions (OSSINDEX):

  • cpe:2.3:a:org.bouncycastle:bcpkix-jdk18on:1.84:*:*:*:*:*:*:*

bcprov-jdk18on-1.84.jar

Description:

The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains the  JCA/JCE provider and low-level API for the BC Java version 1.84 for Java 1.8 and later.

License:

Bouncy Castle Licence: https://www.bouncycastle.org/licence.html
File Path: /home/grprdist/.m2/repository/org/bouncycastle/bcprov-jdk18on/1.84/bcprov-jdk18on-1.84.jar
MD5: 19523b0cbcbce2fdeb98e3eaf68f602e
SHA1: 2d5651789941d2f8ae9b8771f23356de6b61e96b
SHA256:64d6c5a6121fcd927152dd182cbed39afe0fda641a970d9bcc0c9cb1858b2731
Referenced In Project/Scope: Grouper UI:compile
bcprov-jdk18on-1.84.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

CVE-2026-8763 (OSSINDEX)  

In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
CWE-295 Improper Certificate Validation

CVSSv2:
  • Base Score: HIGH (9.300000190734863)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

References:

Vulnerable Software & Versions (OSSINDEX):

  • cpe:2.3:a:org.bouncycastle:bcprov-jdk18on:1.84:*:*:*:*:*:*:*

CVE-2026-12803 (OSSINDEX)  

In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery). This issue also affects Bouncy Castle for Java LTS before 2.73.12.
CWE-354 Improper Validation of Integrity Check Value

CVSSv2:
  • Base Score: HIGH (8.699999809265137)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

References:

Vulnerable Software & Versions (OSSINDEX):

  • cpe:2.3:a:org.bouncycastle:bcprov-jdk18on:1.84:*:*:*:*:*:*:*

CVE-2026-12816 (OSSINDEX)  

In Bouncy Castle for Java before 1.85, IESEngine stream-mode MAC forgery via length-dependent KDF split. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
CWE-354 Improper Validation of Integrity Check Value

CVSSv2:
  • Base Score: HIGH (8.699999809265137)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

References:

Vulnerable Software & Versions (OSSINDEX):

  • cpe:2.3:a:org.bouncycastle:bcprov-jdk18on:1.84:*:*:*:*:*:*:*

CVE-2026-58059 (OSSINDEX)  

In Bouncy Castle for Java before 1.85, Quadratic-time escaping when stringifying X.500 distinguished names. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
CWE-407 Inefficient Algorithmic Complexity

CVSSv2:
  • Base Score: HIGH (8.699999809265137)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

References:

Vulnerable Software & Versions (OSSINDEX):

  • cpe:2.3:a:org.bouncycastle:bcprov-jdk18on:1.84:*:*:*:*:*:*:*

CVE-2026-58060 (OSSINDEX)  

In Bouncy Castle for Java before 1.85, HSS public-key level count unbounded, enabling huge allocation on verify. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
CWE-789 Memory Allocation with Excessive Size Value

CVSSv2:
  • Base Score: HIGH (8.699999809265137)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

References:

Vulnerable Software & Versions (OSSINDEX):

  • cpe:2.3:a:org.bouncycastle:bcprov-jdk18on:1.84:*:*:*:*:*:*:*

CVE-2026-13586 (OSSINDEX)  

In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS). This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv2:
  • Base Score: MEDIUM (5.300000190734863)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

References:

Vulnerable Software & Versions (OSSINDEX):

  • cpe:2.3:a:org.bouncycastle:bcprov-jdk18on:1.84:*:*:*:*:*:*:*

CVE-2026-58063 (OSSINDEX)  

In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted file. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv2:
  • Base Score: MEDIUM (5.300000190734863)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

References:

Vulnerable Software & Versions (OSSINDEX):

  • cpe:2.3:a:org.bouncycastle:bcprov-jdk18on:1.84:*:*:*:*:*:*:*

bcutil-jdk18on-1.84.jar

Description:

The Bouncy Castle Java APIs for ASN.1 extension and utility APIs used to support bcpkix and bctls. This jar contains  APIs for Java 1.8 and later.

License:

Bouncy Castle Licence: https://www.bouncycastle.org/licence.html
File Path: /home/grprdist/.m2/repository/org/bouncycastle/bcutil-jdk18on/1.84/bcutil-jdk18on-1.84.jar
MD5: 7389259785516495923c3a1480cd87eb
SHA1: 79bfd1f9c6bd7431ff22e29935ec20f12f0af0d3
SHA256:b374e16963421fb9cfb01cc20d7ad8fd2f8b8188e3eef0ec0a8965e245f7619a
Referenced In Project/Scope: Grouper UI:compile
bcutil-jdk18on-1.84.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

bsh-2.0b5.jar

Description:

BeanShell is a small, free, embeddable Java source interpreter with object scripting language features,
        written in Java. BeanShell dynamically executes standard Java syntax and extends it with common scripting
        conveniences such as loose types, commands, and method closures like those in Perl and JavaScript.
    

License:

GNU LESSER GENERAL PUBLIC LICENSE: http://www.gnu.org/copyleft/lesser.html
File Path: /home/grprdist/.m2/repository/org/beanshell/bsh/2.0b5/bsh-2.0b5.jar
MD5: 02f72336919d06a8491e82346e10b4d5
SHA1: fdc2ab6ae8b53e0d4761b296c116df747cd85199
SHA256:6232199563807354b3bcb5aceb3dc136502f022c6b0ef743987a83f66fee5a5c
Referenced In Project/Scope: Grouper UI:compile
bsh-2.0b5.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

CVE-2016-2510  

BeanShell (bsh) before 2.0b6, when included on the classpath by an application that uses Java serialization or XStream, allows remote attackers to execute arbitrary code via crafted serialized data, related to XThis.Handler.
CWE-19 Data Processing Errors

CVSSv3:
  • Base Score: HIGH (8.1)
  • Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:2.2/RC:R/MAV:A
CVSSv2:
  • Base Score: MEDIUM (6.8)
  • Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:P

References:

Vulnerable Software & Versions: (show all)

byte-buddy-1.12.18.jar

Description:

        Byte Buddy is a Java library for creating Java classes at run time.
        This artifact is a build of Byte Buddy with all ASM dependencies repackaged into its own name space.
    

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/net/bytebuddy/byte-buddy/1.12.18/byte-buddy-1.12.18.jar
MD5: aa9260b3a85969a1a37c192c63d07df3
SHA1: 875a9c3f29d2f6f499dfd60d76e97a343f9b1233
SHA256:39200c13a72b6a3f4ec43c7b6d2fb78ecbeb25c29e986f4efa572636b39d750e
Referenced In Project/Scope: Grouper UI:compile
byte-buddy-1.12.18.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

c3p0-0.12.0.jar

Description:

A mature JDBC3+ Connection pooling library

License:

LGPL-2.1-or-later: https://spdx.org/licenses/LGPL-2.1-or-later.html
EPL-1.0: https://spdx.org/licenses/EPL-1.0.html
File Path: /home/grprdist/.m2/repository/com/mchange/c3p0/0.12.0/c3p0-0.12.0.jar
MD5: 5b4a3fd8ac111672a231d5c1560bd19a
SHA1: 9c912c2d5b43bdef90ea33ad7c4cdbf5204c6515
SHA256:4d85a7d4643a22df7e9e21a159e022de462530727443ec83d190321eb305851d
Referenced In Project/Scope: Grouper UI:compile
c3p0-0.12.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

CVE-2026-55223 (OSSINDEX)  

com.mchange/c3p0 - Deserialization Gadget via JDBC DataSource JavaBean Property Lookup [CVE-2026-55223]
CWE-502 Deserialization of Untrusted Data

CVSSv3:
  • Base Score: HIGH (8.100000381469727)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

References:

Vulnerable Software & Versions (OSSINDEX):

  • cpe:2.3:a:com.mchange:c3p0:0.12.0:*:*:*:*:*:*:*

c3p0-oracle-thin-extras-0.9.5.jar

Description:

a JDBC Connection pooling / Statement caching library

License:

GNU Lesser General Public License, Version 2.1: http://www.gnu.org/licenses/lgpl-2.1.html
Eclipse Public License, Version 1.0: http://www.eclipse.org/org/documents/epl-v10.php
File Path: /home/grprdist/.m2/repository/com/google/code/maven-play-plugin/com/mchange/c3p0-oracle-thin-extras/0.9.5/c3p0-oracle-thin-extras-0.9.5.jar
MD5: 06b6bb3df31e56a391a5815d0f132715
SHA1: ae706b22bae360f5d360b2a5d207f804a3729ec2
SHA256:d185e4fb6a0165a39a2b85650efa18722ca9b4badef52a7701f081d9ae5ac321
Referenced In Project/Scope: Grouper UI:compile
c3p0-oracle-thin-extras-0.9.5.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

CVE-2019-5427  

c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.
CWE-776 Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A
CVSSv2:
  • Base Score: MEDIUM (5.0)
  • Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P

References:

Vulnerable Software & Versions: (show all)

cglib-3.3.0.jar

File Path: /home/grprdist/.m2/repository/cglib/cglib/3.3.0/cglib-3.3.0.jar
MD5: 6ff304cc2874dd20277a8206fee5fd9a
SHA1: c956b9f9708af5901e9cf05701e9b2b1c25027cc
SHA256:9fe0c26d7464140ccdfe019ac687be1fb906122b508ab54beb810db0f09a9212
Referenced In Project/Scope: Grouper UI:compile
cglib-3.3.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

classmate-1.5.1.jar

Description:

Library for introspecting types with full generic information
        including resolving of field and method types.
    

License:

Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/com/fasterxml/classmate/1.5.1/classmate-1.5.1.jar
MD5: e91fcd30ba329fd1b0b6dc5321fd067c
SHA1: 3fe0bed568c62df5e89f4f174c101eab25345b6c
SHA256:aab4de3006808c09d25dd4ff4a3611cfb63c95463cfd99e73d2e1680d229a33b
Referenced In Project/Scope: Grouper UI:compile
classmate-1.5.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

commons-beanutils-1.11.0.jar

Description:

Apache Commons BeanUtils provides an easy-to-use but flexible wrapper around reflection and introspection.

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/commons-beanutils/commons-beanutils/1.11.0/commons-beanutils-1.11.0.jar
MD5: 32ed51f196dfda19e0dc1ce53eeed29e
SHA1: ac03ea606d13de04c2e4508227680faff151f491
SHA256:9e44ba68ec9a3f21286fa2a8bbb003b735c0f69101bb43144b79f4f8aaa74709
Referenced In Project/Scope: Grouper UI:compile
commons-beanutils-1.11.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper-ui@7.0.0-SNAPSHOT

Identifiers

commons-cli-1.11.0.jar

Description:

    Apache Commons CLI provides a simple API for presenting, processing, and validating a Command Line Interface.
  

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/commons-cli/commons-cli/1.11.0/commons-cli-1.11.0.jar
MD5: e689f5e4947368dd0233fc28f613f561
SHA1: a461452d3e31bebf2706323f8738ec44b19c96e1
SHA256:8f7f8605d68e15bf32db61ec94eac6fdafc51b1bdbe1e0e0802b57d23f387792
Referenced In Project/Scope: Grouper UI:compile
commons-cli-1.11.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

commons-codec-1.20.0.jar

Description:

     The Apache Commons Codec component contains encoders and decoders for
     formats such as Base16, Base32, Base64, digest, and Hexadecimal. In addition to these
     widely used encoders and decoders, the codec package also maintains a
     collection of phonetic encoding utilities.
  

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/commons-codec/commons-codec/1.20.0/commons-codec-1.20.0.jar
MD5: 3fb10a4c7cc664241cc4ca8a0e10b0b8
SHA1: 6a671d1c456a875ff61abec63216f754078bb0ed
SHA256:6af66595f9f6a7bb58ce66518d6888d40b547c366d2262f06676eee19528ff66
Referenced In Project/Scope: Grouper UI:compile
commons-codec-1.20.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

commons-collections-3.2.2.jar

Description:

Types that extend and augment the Java Collections Framework.

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/commons-collections/commons-collections/3.2.2/commons-collections-3.2.2.jar
MD5: f54a8510f834a1a57166970bfc982e94
SHA1: 8ad72fe39fa8c91eaaf12aadb21e0c3661fe26d5
SHA256:eeeae917917144a68a741d4c0dff66aa5c5c5fd85593ff217bced3fc8ca783b8
Referenced In Project/Scope: Grouper UI:compile
commons-collections-3.2.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper-ui@7.0.0-SNAPSHOT

Identifiers

commons-csv-1.14.1.jar

Description:

The Apache Commons CSV library provides a simple interface for reading and writing CSV files of various types.

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/org/apache/commons/commons-csv/1.14.1/commons-csv-1.14.1.jar
MD5: b8119900179992cf139005db63481103
SHA1: 467354980fade8528b6a9f9bdf7f4f19ab9b3373
SHA256:32be0e1e76673092f5d12cb790bd2acb6c2ab04c4ea6efc69ea5ee17911c24fe
Referenced In Project/Scope: Grouper UI:compile
commons-csv-1.14.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

commons-dbcp-1.4.jar

Description:

Commons Database Connection Pooling

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/commons-dbcp/commons-dbcp/1.4/commons-dbcp-1.4.jar
MD5: b004158fab904f37f5831860898b3cd9
SHA1: 30be73c965cc990b153a100aaaaafcf239f82d39
SHA256:a6e2d83551d0e5b59aa942359f3010d35e79365e6552ad3dbaa6776e4851e4f6
Referenced In Project/Scope: Grouper UI:compile
commons-dbcp-1.4.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

commons-digester-2.1.jar

Description:

    The Digester package lets you configure an XML to Java object mapping module
    which triggers certain actions called rules whenever a particular 
    pattern of nested XML elements is recognized.
  

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/commons-digester/commons-digester/2.1/commons-digester-2.1.jar
MD5: 528445033f22da28f5047b6abcd1c7c9
SHA1: 73a8001e7a54a255eef0f03521ec1805dc738ca0
SHA256:e0b2b980a84fc6533c5ce291f1917b32c507f62bcad64198fff44368c2196a3d
Referenced In Project/Scope: Grouper UI:compile
commons-digester-2.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

commons-digester3-3.2.jar

Description:

    The Apache Commons Digester package lets you configure an XML to Java
    object mapping module which triggers certain actions called rules whenever
    a particular pattern of nested XML elements is recognized.
  

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/org/apache/commons/commons-digester3/3.2/commons-digester3-3.2.jar
MD5: 41d2c62c7aedafa7a3627794abc83f71
SHA1: c3f68c5ff25ec5204470fd8fdf4cb8feff5e8a79
SHA256:1c150e3d2df4b4237b47e28fea2079fb0da324578d5cca6a5fed2e37a62082ec
Referenced In Project/Scope: Grouper UI:compile
commons-digester3-3.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

commons-exec-1.6.0.jar

Description:

Apache Commons Exec is a library that reliably executes external processes from within the JVM.

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/org/apache/commons/commons-exec/1.6.0/commons-exec-1.6.0.jar
MD5: 4deb5b2892d0f27bdd9ae61037eec8d5
SHA1: d24a2fd672c3c278e60388bef656d9d89cf9df4f
SHA256:13dcf3850478ef8de5d24d298a60eed5e8305eb20538fe632c82ea1dff6b5ea0
Referenced In Project/Scope: Grouper UI:compile
commons-exec-1.6.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

commons-fileupload-1.6.0.jar

Description:

    The Apache Commons FileUpload component provides a simple yet flexible means of adding support for multipart
    file upload functionality to servlets and web applications.
  

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/commons-fileupload/commons-fileupload/1.6.0/commons-fileupload-1.6.0.jar
MD5: c10bfd8952ec31282fffd3b2625d87ce
SHA1: 2392704cccb4632b3ccd9b8cfbe2943cca6fc455
SHA256:9383272c93569afeabedb16923a94a6dc8a5bd7a2f9f83bf326af4ee68434629
Referenced In Project/Scope: Grouper UI:compile
commons-fileupload-1.6.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper-ui@7.0.0-SNAPSHOT

Identifiers

commons-io-2.21.0.jar

Description:

The Apache Commons IO library contains utility classes, stream implementations, file filters,
file comparators, endian transformation classes, and much more.
  

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/commons-io/commons-io/2.21.0/commons-io-2.21.0.jar
MD5: bc7e020873f086ede85f97bd9f013215
SHA1: 52a6f68fe5afe335cde95461dd5c3412f04996f7
SHA256:7d643a2afea8b058b762aa6fb90e5b256f6c729739f8b3784c3370ddc609e88d
Referenced In Project/Scope: Grouper UI:compile
commons-io-2.21.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper-ui@7.0.0-SNAPSHOT

Identifiers

commons-jexl-2.1.1.jar

Description:

The Commons Jexl library is an implementation of the JSTL Expression Language with extensions.

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/org/apache/commons/commons-jexl/2.1.1/commons-jexl-2.1.1.jar
MD5: 4ad8f5c161dd3a50e190334555675db9
SHA1: 6ecc181debade00230aa1e17666c4ea0371beaaa
SHA256:03c9a9fae5da78ce52c0bf24467cc37355b7e23196dff4839e2c0ff018a01306
Referenced In Project/Scope: Grouper UI:compile
commons-jexl-2.1.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

commons-jexl3-3.6.1.jar

Description:

Apache Commons JEXL is a library that enables the implementation of scripting features in Java applications and frameworks.

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/org/apache/commons/commons-jexl3/3.6.1/commons-jexl3-3.6.1.jar
MD5: 08398f44e46ea4d2b26699077db6a5fe
SHA1: a8185d7ac95845629ae7be1a84677f08f60622b6
SHA256:d3b97d7bb4b8ded378800cc951402ba26c93ba1e88bb867190bf3e232fdc9c0e
Referenced In Project/Scope: Grouper UI:compile
commons-jexl3-3.6.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

commons-lang3-3.20.0.jar

Description:

  Apache Commons Lang, a package of Java utility classes for the
  classes that are in java.lang's hierarchy, or are considered to be so
  standard as to justify existence in java.lang.

  The code is tested using the latest revision of the JDK for supported
  LTS releases: 8, 11, 17, 21 and 25 currently.
  See https://github.com/apache/commons-lang/blob/master/.github/workflows/maven.yml
  
  Please ensure your build environment is up-to-date and kindly report any build issues.
  

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/org/apache/commons/commons-lang3/3.20.0/commons-lang3-3.20.0.jar
MD5: 4b29562ded527aa074e1d44f8646dac5
SHA1: 65897b3e5731220962e659e001904af3c3cbeba9
SHA256:69e5c9fa35da7a51a5fd2099dfe56a2d8d32cf233e2f6d770e796146440263f4
Referenced In Project/Scope: Grouper UI:compile
commons-lang3-3.20.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper-ui@7.0.0-SNAPSHOT

Identifiers

commons-logging-1.3.5.jar

Description:

Apache Commons Logging is a thin adapter allowing configurable bridging to other,
    well-known logging systems.

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/commons-logging/commons-logging/1.3.5/commons-logging-1.3.5.jar
MD5: 9ca067b073153c86c2da350c0f2cdf70
SHA1: a3fcc5d3c29b2b03433aa2d2f2d2c1b1638924a1
SHA256:6d7a744e4027649fbb50895df9497d109f98c766a637062fe8d2eabbb3140ba4
Referenced In Project/Scope: Grouper UI:compile
commons-logging-1.3.5.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper-ui@7.0.0-SNAPSHOT

Identifiers

commons-math-1.2.jar

Description:

The Math project is a library of lightweight, self-contained mathematics and statistics components addressing the most common practical problems not immediately available in the Java programming language or commons-lang.

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/commons-math/commons-math/1.2/commons-math-1.2.jar
MD5: 5d3ce091a67e863549de4493e19df069
SHA1: 3955b41fe9f3c0469bd873331940674812d09bd2
SHA256:429ad6e1a650bc924a3e26fafc8ef703147375d8dd6d02b710c655071cc82270
Referenced In Project/Scope: Grouper UI:compile
commons-math-1.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

commons-pool-1.6.jar

Description:

Commons Object Pooling Library

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/commons-pool/commons-pool/1.6/commons-pool-1.6.jar
MD5: 5ca02245c829422176d23fa530e919cc
SHA1: 4572d589699f09d866a226a14b7f4323c6d8f040
SHA256:46c42b4a38dc6b2db53a9ee5c92c63db103665d56694e2cfce2c95d51a6860cc
Referenced In Project/Scope: Grouper UI:compile
commons-pool-1.6.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

commons-text-1.15.0.jar

Description:

Apache Commons Text is a set of utility functions and reusable components for processing
    and manipulating text in a Java environment.
  

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/org/apache/commons/commons-text/1.15.0/commons-text-1.15.0.jar
MD5: 756b7c5438d89a0c311d811c1a06d19a
SHA1: 9899093aa40f0199d6c39b131b8f087cdb37e399
SHA256:58d2da30f058512a1e7f914e39241deca4dff5c27a085b4ed2faa9e7208067f6
Referenced In Project/Scope: Grouper UI:compile
commons-text-1.15.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

commons-validator-1.10.1.jar

Description:

    Apache Commons Validator provides the building blocks for both client-side and server-side data validation.
    It may be used standalone or with a framework like Struts.
  

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/commons-validator/commons-validator/1.10.1/commons-validator-1.10.1.jar
MD5: d618186ce8b682c51b1a7e72d11f5c88
SHA1: cdf5c2a69aad509c4db54786f19f1e1ccc471bcf
SHA256:ed74711a78d793ca37f6075e4a1e93d107233dfd20d0bb17e32bad88d38e56aa
Referenced In Project/Scope: Grouper UI:compile
commons-validator-1.10.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

commons-vfs2-2.10.0.jar

Description:

Apache Commons VFS is a Virtual File System library.

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/org/apache/commons/commons-vfs2/2.10.0/commons-vfs2-2.10.0.jar
MD5: df535626616b23cdb5555c40e556155e
SHA1: a306167fdb88152403c8b00595b1502ffacd5b76
SHA256:adf9dfb77a44f7b6e2dba3779cfa7142ab8a1f618eb7a9741083822e8d14be13
Referenced In Project/Scope: Grouper UI:compile
commons-vfs2-2.10.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

content-type-2.3.jar

Description:

Java library for Content (Media) Type representation

License:

The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/com/nimbusds/content-type/2.3/content-type-2.3.jar
MD5: f0fc0d6be73e838863e2197c03a27c3f
SHA1: e3aa0be212d7a42839a8f3f506f5b990bcce0222
SHA256:60349793e006fba96b532cb0c21e10e969fe0db8d87f91c3b9eaf82ba2998895
Referenced In Project/Scope: Grouper UI:compile
content-type-2.3.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

cron-parser-core-3.5.jar

File Path: /home/grprdist/.m2/repository/net/redhogs/cronparser/cron-parser-core/3.5/cron-parser-core-3.5.jar
MD5: 2f2639ea2d39fdbed58c815c1fd9c5b5
SHA1: efd36275f5b8a4f0a6b2e48de26f512dee8caedd
SHA256:1313ee514658e2e1755144c3894ab0e2bd88fb2ea4bc99226ea1566c0f6fab3f
Referenced In Project/Scope: Grouper UI:compile
cron-parser-core-3.5.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper-ui@7.0.0-SNAPSHOT

Identifiers

csrfguard-4.1.4.jar

Description:

OWASP CSRFGuard is a library that implements a variant of the synchronizer token pattern to mitigate the risk of Cross-Site Request Forgery (CSRF) attacks.

File Path: /home/grprdist/.m2/repository/org/owasp/csrfguard/4.1.4/csrfguard-4.1.4.jar
MD5: 7a8913a0d0cb554bb84ef0871716db3d
SHA1: 8590d9f54d2179ff2af16f718e9f22abdeb6f317
SHA256:5de5e1df57b5c54a84b2c59adde4b51bf8b1735165feb5bec3cfb84f8b37b366
Referenced In Project/Scope: Grouper UI:compile
csrfguard-4.1.4.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper-ui@7.0.0-SNAPSHOT

Identifiers

CVE-2021-28490 (OSSINDEX)  

In OWASP CSRFGuard through 3.1.0, CSRF can occur because the CSRF cookie may be retrieved by using only a session token.

Sonatype's research suggests that this CVE's details differ from those defined at NVD. See https://guide.sonatype.com/vulnerability/CVE-2021-28490 for details
CWE-352 Cross-Site Request Forgery (CSRF)

CVSSv3:
  • Base Score: HIGH (8.800000190734863)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

References:

Vulnerable Software & Versions (OSSINDEX):

  • cpe:2.3:a:org.owasp:csrfguard:4.1.4:*:*:*:*:*:*:*

csrfguard-4.1.4.jar: csrfguard.js

File Path: /home/grprdist/.m2/repository/org/owasp/csrfguard/4.1.4/csrfguard-4.1.4.jar/META-INF/csrfguard.js
MD5: 0e05e024b3f928ae41163059e9280a15
SHA1: b542548435de656da7eb06a730e44dcd4049b983
SHA256:258e9c1e8b113bb34f0494c2aab8fc5a0c7bd33de82cc63a8fb40ee10523893b
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

csrfguard-jsp-tags-4.1.4.jar

Description:

JSP Tag support

File Path: /home/grprdist/.m2/repository/org/owasp/csrfguard-jsp-tags/4.1.4/csrfguard-jsp-tags-4.1.4.jar
MD5: 74cf22e7e48742a8f238a665129be835
SHA1: 7111cf78de80dcce8357b8db9cc908870c2873b7
SHA256:75d6a3c1d77ababd448b9ef9fc17e0d765315847bdf68c741e485232d3c65b1c
Referenced In Project/Scope: Grouper UI:compile
csrfguard-jsp-tags-4.1.4.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper-ui@7.0.0-SNAPSHOT

Identifiers

dom4j-2.2.0.jar

Description:

flexible XML framework for Java

License:

BSD 3-clause New License: https://github.com/dom4j/dom4j/blob/master/LICENSE
File Path: /home/grprdist/.m2/repository/org/dom4j/dom4j/2.2.0/dom4j-2.2.0.jar
MD5: 6e7161d8e8f5fd0055554374f469abd3
SHA1: 52368b1da663abd44a866c4fe4f62c8d8695204a
SHA256:3fae79e081096e1410645eb3557c63b79ca266d510ab479889511109becd1690
Referenced In Project/Scope: Grouper UI:compile
dom4j-2.2.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

driver-1.57.0.jar

Description:

    This module provides API for discovery and launching of Playwright driver.
  

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver/1.57.0/driver-1.57.0.jar
MD5: 3f907cf8d8471ec457e9d232ae2c0a68
SHA1: 81e1dad481b068ae56c7bc77e8bbcab2fc305176
SHA256:8707b1f2e5f1a6ba3951733adc2385362d03cbeb63366a03f23d9b854011d3c8
Referenced In Project/Scope: Grouper UI:compile
driver-1.57.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

driver-bundle-1.57.0.jar: android.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/android.js
MD5: 032f51733be1cbefc9d9f649ffd8965d
SHA1: fd0cdbbac00172f61702038b6cd0a5e6857d968c
SHA256:dee4274366dad011c01a89e8463ab6215c24efcfc7d880a4803b35ef5e4d2e92
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: android.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/android/android.js
MD5: 9f2e98bee33885df64d230e0f30df2bd
SHA1: 526ee47a5cbc7c27d56a38708b6eb3c73ccd250f
SHA256:7abf032259dbc0519befa528add221474fdc945723116e98e7f2465f8638958c
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: androidDispatcher.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/dispatchers/androidDispatcher.js
MD5: 31c63f287e25b073d27d6cfef7b049ef
SHA1: b0333322c98beee8c8c39b41d0b956686b0b1588
SHA256:2c112dcbdafaff6c01e6873cca79806b2a804833996f81d50974bd405f8a2cf9
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: androidServerImpl.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/androidServerImpl.js
MD5: e41a7fb4ec894e9da9273c9bb4d7c6c1
SHA1: dc182ba77750e979ac7727a03b807975f8fcddbb
SHA256:d00fd955f77ce3aa3deea6f12083773443fd24089e1426b51d01926c2f951441
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: api.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/api.js
MD5: 9774e454f318da9c697ce6d701bf3cb8
SHA1: 23e12a5da0146269016b85f67fb82ff8610fbb46
SHA256:ec61382d31b1bbe37988400d16b2fb17171c183825023353ad4b7790d58f6965
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: ariaSnapshot.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/utils/isomorphic/ariaSnapshot.js
MD5: 4cd2bde16967754a49e5bb1175f968a6
SHA1: 9402354769b82b11a4433b66e020ca491a421c26
SHA256:db285a5036e69e247e6030f9967c1fa98f10183cf59cf136460c9a6b014570cd
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: artifact.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/artifact.js
MD5: 2d9e5fdf8ab5105c1afe550d96b29d52
SHA1: dd5d6a7d3414906ec360be334260441d9566e8f8
SHA256:b8e65f541e490d65b0f888ea96ea97c5f5091342e5ac4a39fa88cafd72e3e04f
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: artifact.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/artifact.js
MD5: 242db954d7f865c9d6328301ecfbcf5b
SHA1: 6d70e5332a056e8203338b894b19dcc6b22cc553
SHA256:009967e1064ea0b24f3a7e7a107381a4b838421c5505b2e39443c3e47dbfd104
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: artifactDispatcher.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/dispatchers/artifactDispatcher.js
MD5: e2b00aa355d401f75225589963a2d231
SHA1: c984cb3f5433cbe4609db0b7416006687df97d6c
SHA256:2d433905daece8a356e9706ed02a7f31e3b0f51b091bc177917858f4ac057ab3
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: ascii.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/utils/ascii.js
MD5: ba2f2d6462e5c8d7f796416479c8649d
SHA1: 53c186a1f5b5c8f3441885ab3c196cc6ffd7e3c6
SHA256:0b7ad5b4adef3d0f64a5372ed2ad9cd778743474e4cef7fd9e68e825c07e1bad
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: assert.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/utils/isomorphic/assert.js
MD5: cb2e0a3f96763a20296c74600a6a3104
SHA1: be78bd15fb0248cea220f807042fdece7aabd782
SHA256:918208119d469550f0384c8858d3b5cb4cb0d7c81b4890f50e234ed74787db0e
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: backendAdb.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/android/backendAdb.js
MD5: 1dbdfaf639c75bb6978375e8021e698b
SHA1: 8c2faf9391189b99fd02eb4de7e529ec84592bb7
SHA256:b08cfc57edc963933597f26c7c8559a251d7094128887358d198278db0c3899a
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: bidiBrowser.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/bidi/bidiBrowser.js
MD5: 49977c78111f23482a3a6b15a3e1162b
SHA1: a8a8621bde4024239c5d75ea070d3428e843beac
SHA256:30abc1842057ffe01850e04e51ffb61d2b17dfff3d4895d93bba6d4c9dbfebc5
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: bidiChromium.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/bidi/bidiChromium.js
MD5: a6965760787900f63777858f25d9bc8b
SHA1: 2efca79ea64ae85e605706f3aa5a9736d6138260
SHA256:88ccbe2ec5aeb793fd751579e6a622cd8439eb8c3e586a632aed08bcbe0b719d
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: bidiCommands.d.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/bidi/third_party/bidiCommands.d.js
MD5: 0660732fa97e26d4823c82bdedcaf3eb
SHA1: 8f744503a5b3e478205f02924545153ad1deb25f
SHA256:2c19fb6cbf950b617fa03de12bc1afca627d2edd39a20381710a05f9ae2d74ef
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: bidiConnection.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/bidi/bidiConnection.js
MD5: 0e7de5690041ae5b03a46e0300b46d3f
SHA1: e2ed96b7a5157724799901aed25f35c3a5402942
SHA256:265872b4d04f8f49c922ca672ddd3816816865d4750697ab534ada5bee941617
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: bidiDeserializer.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/bidi/third_party/bidiDeserializer.js
MD5: 3a28b43ff859d4d21c74f26841a74a38
SHA1: 46ef7b240b0b58c1986f76e971944fa076b80386
SHA256:da5249908dea0b9515fe624ffc5c531e917024c431b498c03e91b95b9d48418d
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: bidiExecutionContext.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/bidi/bidiExecutionContext.js
MD5: 17e73ca1b47a6476a1ea7183e64ee8cb
SHA1: e9dc2ebfa40310bbf86677308dad7240a2f17b03
SHA256:a2e6a09eec2077a380f57159b972b64b0e1e8a9967f8965481ca67007fd63374
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: bidiFirefox.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/bidi/bidiFirefox.js
MD5: 51c15ae5c167c151f55dd4cdbff45724
SHA1: 3c8db5472605c00167db37222298eb39262483d6
SHA256:a08b727a22d8363547b774c42746b7a0de55f65861f2ca45a36179cf70727394
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: bidiInput.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/bidi/bidiInput.js
MD5: 2cb22d98d1b90fae823d82a099c761aa
SHA1: ba34fa625222412f32437b8b276427fb2f417dd9
SHA256:e79b48cc5c6a9d9794398ff1ba507f454878cf9d33264c01c88fe54843edc150
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: bidiKeyboard.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/bidi/third_party/bidiKeyboard.js
MD5: 23a7376a014498f0f30f87ea95ef4af6
SHA1: 659d5a8dfcbbe4c61132262861cb6eb1e158b410
SHA256:a74c4ebcdebf0345217ef8d3e7439633be22ff446c074d75872b61ae74ee9d92
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: bidiNetworkManager.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/bidi/bidiNetworkManager.js
MD5: 3c299a6a5aba74024be024c6ec479068
SHA1: c5a3227e798c31145fc215afef68e681744e59a5
SHA256:a85cf87e05129542f6f74d4b73bc3ccc8a8b09e5b75911b5bf29436c42cfe977
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: bidiOverCdp.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/bidi/bidiOverCdp.js
MD5: 91bd486e660ad1d9442a6330847fd765
SHA1: 9caa3b84167f7ab129f528d4b22cc7c23b838cc1
SHA256:c53568fe671ac09c49bb513d1d029775c05bed301bce9706a6e1792b8d37e89a
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: bidiPage.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/bidi/bidiPage.js
MD5: ab5ef9314ae149dfb1199e7eb3e181c6
SHA1: 8316ee782d3392c6d32d66e330ec4ad1846d35aa
SHA256:ef5ee7577144331a90087f39fa22967b305385645da28a0a53c8d41f96530f81
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: bidiPdf.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/bidi/bidiPdf.js
MD5: a2baa7a93e5669278e32d5e48a89637c
SHA1: ee42de1c3d2d29f2881ab08d58deeeda6d179b53
SHA256:7e71375faf7415debddb5a0dbdb381cc1836718c2c00c2b533f4455d96175b11
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: bidiProtocol.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/bidi/third_party/bidiProtocol.js
MD5: 7cac6a870c4b4354349564c4e23daece
SHA1: 423ab63cf4ee1914c0c96cc0ad81a4c17204d04b
SHA256:c61ae2a96f5b2eab30d20996f6bf568ec23d0e2c581f3a397fd67229b7d00ec2
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: bidiProtocolCore.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/bidi/third_party/bidiProtocolCore.js
MD5: ed549c4ded6860e778964baf2ae34850
SHA1: 2c3898d7118cb19e60cc165d02deb4b549445934
SHA256:11268f09035eee9d01d9a3604cf4ffeaf27c7502a715e68f9f7c064cf9168856
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: bidiProtocolPermissions.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/bidi/third_party/bidiProtocolPermissions.js
MD5: 1fd6b6d5821fca74748999c8251dbca7
SHA1: eb2ada7840c0d608887702a642403b5472fc82de
SHA256:fac350bc073d54e293f11e8fe2f31afbf8d67bd5f831f4e0f53c0ed86874bc65
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: bidiSerializer.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/bidi/third_party/bidiSerializer.js
MD5: fe2dcd21513563d048b30c5262be431e
SHA1: 1e6a6420c48db1a0b331a581d3940d5cd79a9971
SHA256:47e69152456f92ff99400f1487030c812c7e85f3c231e523a28eb35c4519b830
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: bindingsControllerSource.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/generated/bindingsControllerSource.js
MD5: 5aabba356af51a0bbb0e9bbd9e6ec4f1
SHA1: 87d760a8bd7af412ed608b44fc6a560e77473d71
SHA256:e42c78e7d5ba661ff2b10d85fe08cc6a02a550e5209df6c218c212c9c5322c78
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: browser.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/browser.js
MD5: 845da96bedcfd768863debdea5a2ff00
SHA1: cd799d264faac895302a50d94dca95cf0d79dd42
SHA256:17be22b81b9aaed6dd9cb9d7d774007ef1d911db986ce9ee597677f5b3ce3d29
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: browser.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/browser.js
MD5: 06468fcba3e7b491dd2d57eb9752df26
SHA1: d276ec69c3680711d75f96c4551811dc7e689b08
SHA256:4f461d840a29f0eac9fe2a0f10f7cf97c06b2d5ee37f17988540abbb85fae19d
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: browserContext.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/browserContext.js
MD5: 4813b05452cfba7ae3f4b86894eb098e
SHA1: cbbc469365c37480ee33df91ab6ce24070787c2f
SHA256:1c9a5f7e69ccd3e629c40f6fb084d7368e59be3fb46ce5a43ab1ffe7aa9635d5
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: browserContext.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/browserContext.js
MD5: 4cc818427d1d516e245fb507820f9e31
SHA1: f7b48a815c88a1dd2993242d8f8836b5940403a6
SHA256:c8ee093844c67b2054366d76b5f46fd89feb3cc7ffa02ec148f9bdbee5a09491
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: browserContextDispatcher.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/dispatchers/browserContextDispatcher.js
MD5: f9770f60582f042ed7b988b5b80bc365
SHA1: 0aa3cb304f7aa80a30f4acfdcd13f44704e7a906
SHA256:12a4150cd09e4ce406730c94b556028b0bc1f555046bb9a330c6c54ef1a363ec
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: browserDispatcher.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/dispatchers/browserDispatcher.js
MD5: e2cc690a6887d763e71a55bbc82b9e9b
SHA1: a85bba9f6dfda227129654dfc0da990e1d95cb2a
SHA256:cdb74c1daea7c06a6c1e89ebadf26055b2a9912e5efd0a69216d78781603010c
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: browserFetcher.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/registry/browserFetcher.js
MD5: fa49c5cb28797ffa07796be9e15ffff2
SHA1: 87cea525dc28d0745bd2c5d89746614dcca5a41d
SHA256:88d991cb47929caf9505061fffed862f1fb20284cc619d83e45dbd6f41e0b89c
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: browserServerImpl.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/browserServerImpl.js
MD5: e7f4d5c61fd6616dbffb1d3ab089aea7
SHA1: 8c03486acf59d025d9039d594f50632f955291b3
SHA256:fe91e82ae655a4b9f2e9f411a201684e2029684d5b13616c28e655f63bf111f6
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: browserType.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/browserType.js
MD5: 6cb8e15aab5f06f050dd7b58c72ecc06
SHA1: 64db558b3b15fcf5260555840805b2b3456e9ba3
SHA256:a5c3aa4c7580393175b900c6931ba1c7fc28d65757d46d9bf8b22080475961c2
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: browserType.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/browserType.js
MD5: 372704925ed344bde1c207084d376717
SHA1: bad0de85b76c8637715179b7a208b8d7ab9be174
SHA256:79a831a557bf2a96d2d5315e8a0acb1ae206dc3b59d7ff45157514adfc00329d
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: browserTypeDispatcher.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/dispatchers/browserTypeDispatcher.js
MD5: 6799f69782b5593c8742f317050f11ea
SHA1: fe52223d6e0e8187b766f8bb0e006b6868b60529
SHA256:e6765d006d98b873ea33ca91dac5f19db81ceb81a306d159d04c0be4cc2265cb
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: callLog.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/callLog.js
MD5: e05a3db4b8eff97c1917e2911b84939e
SHA1: 9aeb98873934116df7f49dd3c9a35f4a4f447230
SHA256:72b8c4d2b140ff16ac4eae3fecf34d76cae14348e42696715d58d780aa89b298
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: cdpSession.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/cdpSession.js
MD5: c8b5db5d0c49351d65176fab595fd963
SHA1: 9b9165e39db5ac9e079a0208b6205b3935d3da90
SHA256:b69012f85807ae8ad8a5363f82868f86b9d8a51ce35c9cf6c863e1badec0ba2c
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: cdpSessionDispatcher.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/dispatchers/cdpSessionDispatcher.js
MD5: 1bba5367a97a7fd407c5c49817d61f01
SHA1: f9f914254695334ad42b07e1dd7de002f7c784f3
SHA256:a8e89e19d8a40e2f838f3e794d2d548488498491a85281c07b73f30a5630abd1
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: channelOwner.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/channelOwner.js
MD5: bf96d2833b6592ca1b6cc168cf8e87f4
SHA1: 65e93ad19063d26a88042b658b36634cc830b488
SHA256:7052cae26b3fc156572494b9cf8a6cdddc8d3845aea7dec9ef7642f44f866c7e
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: chat.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/recorder/chat.js
MD5: eadd272cca9d494e73e577de0219d258
SHA1: 885b6a0309a34c6ee80ac301341337fae36b98fb
SHA256:1966533863de1077a2c31f0750c08bd60fe123ab6a953247e777dcf101ae9243
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: chromium.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/chromium/chromium.js
MD5: 9ff9322802b4156a8d3d5afd0a470c78
SHA1: 418e54e753cd0a45929b0a4a67948ae80131e0a9
SHA256:0b650987f20f3435a331704ed97c692e62a9f86cd4974beb60a628776e5c7885
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: chromiumSwitches.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/chromium/chromiumSwitches.js
MD5: 0b7819e95b01cf00ec25b481c0cbf01c
SHA1: f9794c5604f4732c46aceaa1b9a76641be9db174
SHA256:32e8e56f0b1483c0c79de3ba1ed8c0dddcf2c1221f51c6af8d6708c6adc09c7c
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: cli.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/cli.js
MD5: 57b2616b7fa731f2d42009a75cdfb31b
SHA1: 526e5faf2a9b80547d3d6d26d41d0f0d28a55027
SHA256:a0ef30b76aa5d64d49b74f454a15cb5fdb063149f3cc4758446941b724851f38
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: clientHelper.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/clientHelper.js
MD5: 2b27a377f72ecb03d484e7f55fd85cd5
SHA1: 29fccc490dceb1f20262dcb00a7bd6629b96018d
SHA256:350fde8c4b69208fccbc286e628eeb8d9048b4d7c6ac48ca7e9bb6f54addc2ce
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: clientInstrumentation.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/clientInstrumentation.js
MD5: 6e5f5ac366b72cf1c9a0818d43652365
SHA1: 763f9ce7b3185cf01c7ef86e612a62883a44e305
SHA256:badcec6bef9fb68dcf04758fd36df6a64c551aff1d8bca5fc98f2e4d756e8d3c
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: clientStackTrace.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/clientStackTrace.js
MD5: 2d03ef6b2f200b0ef958ddea79cc16de
SHA1: 392a599506a44192cef6007ea325d9dc0fa6e0b2
SHA256:8390cf4c31d627df070e174f7c6db879576deec9df07a1bf1779b6bcf65a7907
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: clock.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/clock.js
MD5: f2318f8bf55ccff6bc2b76544397e4a6
SHA1: efeab6870dbe9f05f78b386c7ea891857e704095
SHA256:b2b57e1023b837e75d73476efd4d29145950b39f3583b7967d55d19165a2e3e4
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: clock.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/clock.js
MD5: 738f9d05b3557ca27a90a447713bb538
SHA1: ad46882855014a88fcafec9cd09c4243f016c730
SHA256:cab36df101d3f651ee917842fccba9c62568a09587e18f0b0d932fb99bf6edf4
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: clockSource.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/generated/clockSource.js
MD5: 2117a15e9aa64c4229a99ae4004b8091
SHA1: db1f876800f069e153710b41c3969451d07aee83
SHA256:9925d686b9c1d582e7e9fa75de8f61ec977dd8bccbcb0b2a5fb5cbcf168ad0e8
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: codeMirrorModule-BoWUGj0J.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/vite/recorder/assets/codeMirrorModule-BoWUGj0J.js
MD5: 292dfd212164e4b79766c11ad0303661
SHA1: 0e790dd09890ed1bf094503c8b3c5ae767cd86cb
SHA256:4bb8ef206026eb5aa12b4c94d2d3430e63d5213dc5c851628de00d3793660296
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: codeMirrorModule-Bucv2d7q.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/vite/traceViewer/assets/codeMirrorModule-Bucv2d7q.js
MD5: 219ac12452f6cee381e1de03195338dd
SHA1: c0b8e19853c80309061da0db07d83bb956e86948
SHA256:ba645c56235b9be917fe2f053ed2809d22854094d162661372930a1206115581
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: colorUtils.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/utils/image_tools/colorUtils.js
MD5: 6db4d3b6219a7bbb6055b9fe82b13a32
SHA1: 1a914cabe125780fdb9915244895c8afec1e23a5
SHA256:dfdddc79f4559a097b5f1bb46dcafb3c823c63c78574ebd0941b3d61668b1f9e
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: colors.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/utils/isomorphic/colors.js
MD5: fb37cbce1151b639ea86283b9708dafc
SHA1: eb3eedc70e0bfc9e14d9036dfd45bfef23214c98
SHA256:455701e3f7323b4742fecca2ea67eef41b819bc05ea0dc3ee6af4a076ce58564
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: comparators.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/utils/comparators.js
MD5: fb10f2e752305cf42eb8d64fcc72a33b
SHA1: 4167b2cba6b74e270efcd2aad440d750670d338c
SHA256:751e40a504202e06e2e0a7298a66ca1ffe27e7026cf8c6206c9679b87a7c9639
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: compare.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/utils/image_tools/compare.js
MD5: 69ca3ccbf4b49a7863b364a6a52e824c
SHA1: 12468b3b5d32ffeaa7a849b12bcf1727fcf21e9d
SHA256:038688ba4f1a888e33f7538d325a39d8207a7ddf1e725f4b3060b7284ac537fe
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: connection.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/connection.js
MD5: 34d27c62a92dfa1722cb33cf3e72dc51
SHA1: afef70c6d464bb0fcd73adeb7f96617b8459d863
SHA256:c3c11953b34ca18ef2d28515fab5d2806944474694d55805f73f8d2abafa94a2
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: console.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/console.js
MD5: decfcdd88d7dbacb8d14fbef4cb4302b
SHA1: 550aefe75c90f7f1916e2beca26070e575bfea4b
SHA256:413bd0bb7ae2895f2cf36637f3ef0b8ddba9b737b4d887ac03e96494038316d0
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: consoleMessage.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/consoleMessage.js
MD5: 53ef0c010580de12915b2d1cffc920d5
SHA1: 72c49c81126864fd2b5cfc8626cf28370927e8c9
SHA256:a0a7d1ce5c009fecba5f0ff8b80834861afc9e2943832da803c16e61fc004444
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: cookieStore.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/cookieStore.js
MD5: 7b1f897690de052bf89621a477ce78c9
SHA1: f08f0bf5878578160af285a5a5669ae7ebc3d541
SHA256:eca3a2db95aa593443bc2bdfca182e003aff837feb554dc485fc16780a1777f1
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: coverage.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/coverage.js
MD5: 8440a8e2f8fc79a78a9bd500a65c87cd
SHA1: c00129198d80403e7c90c53b87403dde88ef0ee1
SHA256:72eb9fa60baaa1336e800cc2aa24a907b415d58d9f5186edbd471434879f32ad
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: crBrowser.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/chromium/crBrowser.js
MD5: 3693f1536790814775c3cb5a11c84c51
SHA1: 62d0689e79555b6d5cfd3217e933027116a402bf
SHA256:c72c8906948a54a3d78049148c53c1bacd9dd54cbe2fce48e4e2ad7d032a03b2
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: crConnection.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/chromium/crConnection.js
MD5: 77a27ad49d57853cb34d99c81dd74787
SHA1: 967d54e8b8c1cb51b4aba4620785e9f80750a614
SHA256:b5ce109765dbabe8c96b9f97662d47da79b47a06f038b34f50fa651fa6e2a0ea
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: crCoverage.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/chromium/crCoverage.js
MD5: fb1b4f4f2ed1190935db9aa9527e94f8
SHA1: ff7a63eb343492d927ba97b9a40518151d4bf8d9
SHA256:8bd8e0330abbaf605603315e414132d346a1bbfe33fe55f8fb69389457a0e620
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: crDevTools.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/chromium/crDevTools.js
MD5: 5ebc1a674e89b3c29671fbce1dcc1443
SHA1: b68ecf68f01a97e12a8cb2071f4577ab5f4174cb
SHA256:bbc56f5bbd7fa04c3ceea9da93c6ebcca43b2394ef4b9ea0386e5ff4a46f9d09
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: crDragDrop.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/chromium/crDragDrop.js
MD5: 03e865fcbfc349a3efe9b389159b204e
SHA1: 852e29fdef917f331327272bc664eedd9801d0d9
SHA256:4920b5cc049666f56dc0a9d75ad59b1e9000b62af97dec92cd3908d7a93570cc
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: crExecutionContext.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/chromium/crExecutionContext.js
MD5: 1bdcd080eb078bba8faac6c6b951f18a
SHA1: d7c142e737ae7760ec2fec5b9166c7d90a2828a8
SHA256:4b4da27c16c2ec7094dcc3cc78313eb9ac8f15a9ed3b7589118a883d6d339b7f
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: crInput.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/chromium/crInput.js
MD5: 151f3c717b8fd460e8f7235e5a9cd0e5
SHA1: 85396fa157801c3e6b5d9cd01fa3974c5d127581
SHA256:3dcad19b8f52f3f1f9787c5fff350607e242cd0d0c6911223c9d44bed9a75432
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: crNetworkManager.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/chromium/crNetworkManager.js
MD5: b3c8b79d07ff2bd9eef795a165609663
SHA1: d68b207a0286781cc71a0ffad42e83d40a25ab22
SHA256:55562bd3e4c190d3306c0ff1504655e7521889f25994bd6ac88d3f405693fadb
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: crPage.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/chromium/crPage.js
MD5: a785b436dfec91642fa5be067d3537be
SHA1: 3078560ed1b9fccbcc15f9c973f8dd8fb30841db
SHA256:71aab16b0912f23cb9aa3095b8072bfc6fbd6e47e4e13a7be3684b796aa1cd28
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: crPdf.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/chromium/crPdf.js
MD5: 4e35cb84c7a8b221300a030da364c0ba
SHA1: 5eca36b29733cf030df2499acbcf53f89a482698
SHA256:821fc8d7d58a91fbf6b1298617c3f37b4f4557a64b8ba2c07ae75f9090e9d606
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: crProtocolHelper.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/chromium/crProtocolHelper.js
MD5: 8a30a3a2886959570baa9da39eede30c
SHA1: 3e95c889292825f24a154118a54ce72cbab3d49c
SHA256:1c35341f0f086fd4a5b9b3f80508039814d59d563e1775506228d74341e111c7
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: crServiceWorker.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/chromium/crServiceWorker.js
MD5: 3da91875272271cb3d877c104402f72c
SHA1: 184e4e80203be81b41dda18096924bc2248d4231
SHA256:31f02cbb18100ae55eca5785ae81021bf7970fd342fe2d42014245fe76ca3f95
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: crypto.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/utils/crypto.js
MD5: 8235939189db83280406cc160f3de2e6
SHA1: 1eeafd591b33f0be44012a0a49990cd241d39e9f
SHA256:0c145da88e7300555b77c10b6b1fa1090529019e11268d298a00514894c5f44d
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: csharp.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/codegen/csharp.js
MD5: 4a59685fb778f1c9da86fa595058bf8d
SHA1: 2365e9d536981cbf293938a519fd739725724c42
SHA256:dd546e17850fc2a398ac5345545769722d955d9cbb38739bab32d45a7c79dc3b
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: cssParser.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/utils/isomorphic/cssParser.js
MD5: 683816dc8e2cf4f2b81f1b33986ad5a7
SHA1: dc618424cbd09ffd354f6354faa58e726009a83c
SHA256:a1a47a8c04ac4456f29a9bb8516eb3bb4b131828a70f41b7f8d01565229aedd1
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: cssTokenizer.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/utils/isomorphic/cssTokenizer.js
MD5: a8e230fd84bf34bb0310bfb4d1783a48
SHA1: 5b8a93da08436779c83e7392359f9743a0999d7e
SHA256:12e589bbfc994957d0f8b18efb451ad173af6a36b54772cfb6f87ae31c3aeca3
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: debug.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/utils/debug.js
MD5: b5545185cf60aea56d1931c34bf6897f
SHA1: 40296c1d0be71776888f0969f61e112d3f5f6aed
SHA256:7df4ded3602390556958cf4a9795b06217cc5ebcd17af7a3a7dfdcb2a56f4b3f
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: debugController.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/debugController.js
MD5: 90bb70f6dfecec454f447b4188e796b9
SHA1: 8fc99072e2a24bc48a6609d94361b9a4aa0cf086
SHA256:4cc042576e97a16ed1f4df1dd063cb6c01710eda3e6ed1658daf7022fb6c9b52
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: debugControllerDispatcher.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/dispatchers/debugControllerDispatcher.js
MD5: 27d202f8c5001c25e67d132f47ca7941
SHA1: b051a22b6c1d2d0444cca02bcd1f24fc1bc0d0fc
SHA256:ce29b9ac6545d6174befd6f8f39eacecf2a5edb7b6331b48eca003dae259f82b
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: debugLogger.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/utils/debugLogger.js
MD5: 3f8e2e549dccb1f84b3bebd49f9bc040
SHA1: 31b3d5c4dde74d6afcfdfc3e3ab9696bf6548496
SHA256:0fb0eadc66df2ef6537bb873b7e2f278c2b2389a2bbb2cdc908c02dadd0cce79
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: debugger.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/debugger.js
MD5: 86a524b6f2ad8cbe287598846629b062
SHA1: c7cfb66e119a416901a554e9dc1c11bf43760ef8
SHA256:fa3d2b8d268850e9e9a39b44e86de11e5cafd054240ec788bc1b2938d4f73487
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: defaultFontFamilies.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/chromium/defaultFontFamilies.js
MD5: dbe59d2a668887d6ad8abdbd03e1fbd2
SHA1: 6f0bf30b2b8ac9f3c067e858c456e6ac42506938
SHA256:61838aa599e7da94c003162976003e8cdefc029bf5896b82bce3683489f52f44
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: defaultSettingsView-BEpdCv1S.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/vite/traceViewer/assets/defaultSettingsView-BEpdCv1S.js
MD5: fc4e5c433708e4d9a289547f194bc2a7
SHA1: dfd1befd666e3b02f13348e0d37775b17044bac7
SHA256:edd9c8780cd94561621487661505fa8d184fbc2b2ced5ec178006af19bab2f97
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: dependencies.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/registry/dependencies.js
MD5: 30d55734d4171186c143c072f89829a0
SHA1: c7a34840efa158b5b1e7d99bc8a83fd040a89f52
SHA256:e1da2edeb0ce13b3828501ee92b980cacbe7956521544b3bc68a350ad40df2dd
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: deviceDescriptors.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/deviceDescriptors.js
MD5: d35645e13e3bc0e9d4811218a3e18933
SHA1: dff895daf641cd5daa98299b6a471db0ce07782c
SHA256:a3b02cfbcaf3704055e9ddec3f31780b7a624116fd2b04ff296a98c437b1ab98
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: dialog.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/dialog.js
MD5: 813add3c80e9102f5e693198d55294ab
SHA1: 3678b511ebca049f68818af38cd3622b68bbea72
SHA256:6fd36243bec2aaa83f0ccc6ffb922f161c2f0facbee21b713ad3f8b8fb9a540e
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: dialog.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/dialog.js
MD5: a11eccd4a0b268186c3b5baa59dc1aa3
SHA1: 1b0211543c71804b198a2bf8c57abd0f3c6c4123
SHA256:ab5418c584a1ab1931b553b0bf340c48be5b3cff3fdf5e226cbddac88ce35bfa
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: dialogDispatcher.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/dispatchers/dialogDispatcher.js
MD5: 55bcf5aed081214ca1a55d71e7bdd169
SHA1: 43ffd1cc623a95aeb0b7cb7b1adca48626dfaa09
SHA256:8d2f52c5e795f988d663803132876271c973ddd4b4bacb199ab60ace6807bea3
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: dispatcher.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/dispatchers/dispatcher.js
MD5: c1206f79d63962af6993a9332bb3bec4
SHA1: f24849780dd66b2f02b95d72e534509f2786e0f1
SHA256:24b65f4badcae0bcae6affd6813a8e84d7f2d807fc118f2d525c54b28fd2cff8
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: dom.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/dom.js
MD5: 00c7497028c82f44bc12f0dea0d0b4b9
SHA1: 86e3077f0bfe116495fd74ee2d29d8c448d24b85
SHA256:995837465d10603c5d394965cdf7e9e249ca3f1905b2f20cd1e5a7fe85ec1edf
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: download.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/download.js
MD5: 5791e2112105dbc625ecc56007f0d354
SHA1: 6507481c844d135bcc20a4278697cfdfe87e98b9
SHA256:4da5bba721c27be59a3c8a66b6965568bb8739104f59595348a66d4db2ebb239
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: download.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/download.js
MD5: 204ec3c73f76347e6f264c74a3545bef
SHA1: bc3021871474c8e3e6ba7360904bc4c9d3d545e8
SHA256:8c09c06cd71ff9c45572ca5eec076c180ae43ec0359c7005b7f9678d31cb9687
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: driver.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/cli/driver.js
MD5: aea361ee820357d20e7173db723b1465
SHA1: d0dc5489bc67041631b5595c53185d110e23c12d
SHA256:f86aca7cc5acc30c07e9b46fee077fc53e0f97d238124d8695c7ee82e49362ae
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: electron.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/electron.js
MD5: bc6b87f33aba020c307a56191752fe9a
SHA1: fbab62c46ab4cf7b1f001b189018fa1b14c610cf
SHA256:d6e8f20cf628d0251725295dd4cb97fc817791d6146c5c0f1e3743c8a601a698
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: electron.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/electron/electron.js
MD5: e38fe3905d63897dcaad9799877295e4
SHA1: 0f77d60d3d0a3b6a2684cc581f5cf12564c30642
SHA256:8a3d5ff6be47d4a158c3614f2d534b581f0d07e209ecc381583f98281acbe3a8
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: electronDispatcher.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/dispatchers/electronDispatcher.js
MD5: 53ade25a48f1962801edb23172f60df6
SHA1: b38e879ce4c0c7010ec08ff553abdd845d82aaee
SHA256:5ef8a222206fef9a4f2b445c3c6fcb46739809f54528c4c99c4992e4a5634ded
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: elementHandle.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/elementHandle.js
MD5: fd1503d431600b7f9e384829ee1de0ad
SHA1: 6f4f1ec57dfd210ef7c84b647496ecc37d412142
SHA256:697f4a54adf8d3b5456e57b2396f0adcd91f6814c9c147db3292524019f49105
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: elementHandlerDispatcher.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/dispatchers/elementHandlerDispatcher.js
MD5: c77626cbfc6a48c30e4a0476005d6356
SHA1: 77e5f679aa88430b4ba905a214d6b324a79c70ef
SHA256:bc342fc6972c1dad024f71936112b1d8e3e60ea7f6545946caaca464c6f76dc7
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: env.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/utils/env.js
MD5: 6e94e32611447fb4bff3dab8fd99012a
SHA1: e5a7e505f1bd1aa0800f62681b0b7fb357fbc9e5
SHA256:7606cb0eae1b89ce5e8b45399efbaf16723779a2714e74858eca9bb56f93e5ea
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: errors.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/errors.js
MD5: 8723dab82d90108d6fa430cb50825e58
SHA1: 1c08efea64f50c4d39768e0a9f1704d0075814be
SHA256:13ec20bbf18461690043785515025bd3d3bfff8b51afcbf8c4e06dffbc014347
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: errors.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/errors.js
MD5: b313862bebbfd93624f4520bcbaf567f
SHA1: a3d836631c1c5fa91f361c59b9692acb5a163ef9
SHA256:883a5e30085bb7a39f003bca462da5191ee3e9e002298d3ad5250296896afa5b
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: eventEmitter.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/eventEmitter.js
MD5: d5e2d5d66b969b3043ec43c59f0bf99e
SHA1: 441441d4f7b77b03b680731992e70447e4cd7508
SHA256:6d2f3acbfc9cfee5002086dbe676580353b97ce40b3eabf9382d832b04ae3e0b
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: events.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/events.js
MD5: 0501a784bad753a3566b501205a98eee
SHA1: 2059f519d91c87a7f0c15c28e73b4f21c7bd2a3e
SHA256:9fd6531bc899dee4dc01595a4163b8496d464bb1284d9a786dceb05cddfa3fbf
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: eventsHelper.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/utils/eventsHelper.js
MD5: 6725720b440bc1696a61b6eeb77b03b0
SHA1: 4fb71d8c269c3727c7f2ad45a50653f8cb2b1cc4
SHA256:adbf2d345865f2c4156086345bc780f695659359ad110f32c58506f7a95eacc8
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: expectUtils.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/utils/expectUtils.js
MD5: 08c0d0d48e6511de8e2662c4692ae771
SHA1: cbfcfb9d8f6e19edefe539a7e21abad3e6785e13
SHA256:a4c5bd4f1f07b00df3744a0d03f3c7b1df9e90987f9aad745cff84989bba56a0
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: fetch.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/fetch.js
MD5: ab590823a07dc3e37ab71f6de42f0faf
SHA1: 39a1745154ba49e954cf8a15b3df801b9d86644a
SHA256:42c479aea9d3db78b094b41410eaf0a96b25e3498ac7e68371821f5c0bedcc52
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: fetch.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/fetch.js
MD5: ab5f2ec31613800ae25aad40679f3004
SHA1: 45c2d70d2fcbc4f3142e0dfc0f0c1f1ca0457e4e
SHA256:4763a8d6e07088d702b667f6ed9c54eb0a92328032df6ff4d8fc806e1db53f04
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: ffBrowser.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/firefox/ffBrowser.js
MD5: 0c46b93d7b263615fba1ceec5d84cb1f
SHA1: 859d2da2dcf43628fdfbbf851afbc43783b5bbde
SHA256:a75581feabf6e938f5c7ed4a83b4e6f07cafbd30051ee91142c19dad966cc70d
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: ffConnection.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/firefox/ffConnection.js
MD5: a474b89c693bc0b6354cb29c4ed82ff9
SHA1: a0fa9babccab2005c7029c3ab81336223f28c3d1
SHA256:4e02e903fe7c555c6eab26ecf9e367350117b8ce311df29acdc4e515cd46d7d3
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: ffExecutionContext.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/firefox/ffExecutionContext.js
MD5: 92b0673190dd8334b8326ea13b38966b
SHA1: 69d90039fd730c0a2eced4b2c5fffdddef884460
SHA256:0f60d7ec29590aac2a7480545da2fa0397ecd0a0a14928f97d13671740dbbcfa
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: ffInput.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/firefox/ffInput.js
MD5: df0e11085ecf0dd0859adf33590c603b
SHA1: 9a93663b40581eace6d76563a16f41f4fde79a78
SHA256:039993e94c894af993c015ab2297c5c452b2770523e896cb69f0e98df6316e43
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: ffNetworkManager.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/firefox/ffNetworkManager.js
MD5: 8eebdb88a9a24dba9850b55ae182d836
SHA1: 0a7f060617d5d36e32501f22e65a3731891da264
SHA256:1b0b204c48a7e11405e62a822baa82acf233d5655c3f4b2f5cc2cae56c2d3344
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: ffPage.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/firefox/ffPage.js
MD5: ff4d06480fd5807af0715d260d2dd231
SHA1: a447fe303876e682d1cef2a0641ea924c6b16725
SHA256:e3722511c4bff1a88a91f4909e6c127a64141577add8b32525aee9ea58781f21
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: fileChooser.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/fileChooser.js
MD5: ac3af9236a53d3e0f7bc6cc1804f9092
SHA1: a5f773c02c0f6d093e4f56119f7a6fcb3eee2016
SHA256:e4d9ee9810fbfc558327eb154b1a9489324d7389c6cb9d813fa8b1617ca21f0c
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: fileChooser.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/fileChooser.js
MD5: 0fe2996c192cc73f8d00ea6626f9439f
SHA1: 642968367bb28dab89d3d797a51244bdc00df7ae
SHA256:64aaf685f90359c3bc123cf4a4f0bba6a0b4e6e6b42788bc3227076c4b12af70
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: fileUploadUtils.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/fileUploadUtils.js
MD5: 14b0794dd58e97f1fa101b6c518e12a1
SHA1: 93b20bb1a389572056c72455d8c4922c70422a9f
SHA256:5b39d9bdc8e65564b1d830e02f7ce71302656df765f35c90bbc1cbf38794bf32
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: fileUtils.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/fileUtils.js
MD5: d7ec07ca525b578da28e5ae34dda78de
SHA1: e2eaf051334ec70483fd32ec6e54be21b3141bb8
SHA256:1650724633ab1e7c34ef4e27bcb83df383ad488172292de0621963ded2cd22e9
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: fileUtils.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/utils/fileUtils.js
MD5: 1ab513c51aef4c817d373bf2e1777181
SHA1: ef14b4cf97a96f6a87460ff2c69bd3d727f5e165
SHA256:33dcc28aa06a85e9eed175f1210a8142ea9bb495520e993403e390aba117c572
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: firefox.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/firefox/firefox.js
MD5: 89e9ddd2c6faa6e96adbac04bc361afb
SHA1: 071b2ccaf9a126d3640a578b4418b1acf273e440
SHA256:a2aaf4755000d0a55ad1ba8368fca4db7c88fbbfafd2dd181defa794014bdba4
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: firefoxPrefs.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/bidi/third_party/firefoxPrefs.js
MD5: 138dbc913158c17d3550229083871c14
SHA1: fd54b256c9f8a19752b2987d9c051de761c9b199
SHA256:93af4d43b84b7eb42345d0216b72ef7d0c085e6e649d40517bde54471404c84e
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: formData.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/formData.js
MD5: 9518c887e669aff0e368138000612262
SHA1: 8377df02d0ade74dcc46c0be933be194aa8edf40
SHA256:3a88e088f8e649d03f3eeb66695fecf73767fe5dc378454b19eb07ec1465277d
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: frame.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/frame.js
MD5: 20d7d4b9d1ae7502be6c25722e3ad35f
SHA1: 9f82cdc422910addb3adf4802ca1e54623888905
SHA256:5f24820b8baed92e1381508c92dd461a0e53817a6c51afe10326f34fc1261ff6
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: frameDispatcher.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/dispatchers/frameDispatcher.js
MD5: e44c30327df7ab7039d4367e6893a573
SHA1: 8ef9ae38d63f05acac8ec1eeb3985e48bedf10bb
SHA256:3ccc0d1bf44038a3499279d4927f09e93658c089c9d175ba3f3078ff50a1da30
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: frameSelectors.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/frameSelectors.js
MD5: 11ff594cd86e07b91aa39902a41c265c
SHA1: 0d4379b8f2b85e09202e9410db845a669eaf8b87
SHA256:934f6101f6e6c0651805ec0e5c4288f8fc73720ff44133e8a00d0b5de13aeae6
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: frames.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/frames.js
MD5: e663656d959f68ca727645ecbce3819b
SHA1: f6b4ddf60b4840546c481b8b8621e6c6c5a1e29f
SHA256:707fc3b31832b9fba8abfca3b788232404349714a5cc5e3af0c2250892ee767e
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: happyEyeballs.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/utils/happyEyeballs.js
MD5: 2ee4cd2383d68a1cc0531214f3ee3d2b
SHA1: e12dc9602c538bc4c6cae2f8773c436209ee1f5a
SHA256:09b06ef645ea809df49f26aa5c10d703b38abac286536c27672cfb709efacc42
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: harBackend.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/harBackend.js
MD5: 5f20f6f7b271bb763a4d0471e9d0df18
SHA1: d27f4c7a9e907acde1bfd17b60ecad2a3c4b4890
SHA256:f98df2109b57c23f324f3864077c1806dd8e62e778e538acfaa51eb7f3a17643
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: harRecorder.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/har/harRecorder.js
MD5: 9a055e2f2b2c26649ae6bdead23b61b9
SHA1: c5dc41f993c63e9a67802896aaab22af027b4c16
SHA256:eec7d85e5566cad437488c8cf98efea014997bedd8f815abb84a7ea1f04152a1
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: harRouter.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/harRouter.js
MD5: 3ff1e0be212ac80f1e4f53ea81b5a174
SHA1: b8691645aa4a8a53d458a3b2d306934708604c62
SHA256:576628bfac6c968c08f081f224a56c9cb852faf6c2de6eddbc299a3eaa9d0689
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: harTracer.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/har/harTracer.js
MD5: 89489e5341f9027eda86cc79d5be650a
SHA1: c50ea05a4f74eff5815f6a277f8f33b910c63729
SHA256:8c78682cd64c794187ab90e174b8c3b03422b01573236eb09edd20f8387c408f
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: headers.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/utils/isomorphic/headers.js
MD5: eb1c0b0c9ad2ac374e69699ef942b74f
SHA1: 1d216b53d3af960b7bdb0bb0dea028a144857bd0
SHA256:41304e0bb0a0e9b0ee0b4a167bbfacd1592f1bc4d99b3c9c18dc93b7b5f93af9
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: helper.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/helper.js
MD5: c7a59b4ec3f67d1a9db81f961c838c0d
SHA1: 2d273cd8966c2925498f25d4a99c2be841df7a1d
SHA256:2d65592d34fb1e1a43adc6d2cd9d60ce0ff6b3c3b9b9676a61e4d2647dceaa94
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: hostPlatform.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/utils/hostPlatform.js
MD5: b640290b930a40f0ae4c009867e6dc53
SHA1: 188eeb0e421f0b2e52ec6500979ccc57378813f1
SHA256:3724bc6607f26ca77562f9e362fce4beb0e611ed95f127d9d34f31c343421d27
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: httpServer.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/utils/httpServer.js
MD5: 50b881d8f69b93ab1e09f7b03748b7c8
SHA1: b1b3f5aab8581cd83edc9ad309f9174b32abbbd3
SHA256:c654eae1416db82e337035ffcf4e86b580bbf0542bc761946445e4699049fa39
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: imageChannel.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/utils/image_tools/imageChannel.js
MD5: 40d8425953546ebdb0e8b32566600489
SHA1: c0c22afa3b9c4c4b5e378647a5e5633d2d573dbe
SHA256:dd5f5ca4e228aece109162686d103f53bb2e0fa2c0fb0208bddf450677809c7d
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: imageUtils.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/utils/imageUtils.js
MD5: b1975dc96b12b1d1ee96299574b14984
SHA1: af65f66677339f62fb33e1849595756126c3fc52
SHA256:4f1422b374bbdc903bff891d34c5144456e447e90e30ebff8a2b1fc1d426c168
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: inMemorySnapshotter.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/trace/test/inMemorySnapshotter.js
MD5: 7f98e814e7ba4c94c2a195cdbd3312af
SHA1: 76ba6d6f731fc55ea7c1b6d8c11bf8ccf1a8223d
SHA256:cb92bb9d0bf668acde1b4f967b50e0b6eda548eb90bc91ef3345b6563f127555
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: inProcessFactory.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/inProcessFactory.js
MD5: 788fc9bd93f75d257992f55bd5ce46ca
SHA1: 3aead73d57a2f69e2970d515899206541b08fe62
SHA256:406a2ce0e50bf6c695a0fa018ac3dec505b60836710bbab797e11730c51917cc
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: index-DJqDAOZp.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/vite/recorder/assets/index-DJqDAOZp.js
MD5: 22d3163e9ddba547e1f2533b691ab81a
SHA1: c553ae97f155544096ec0d293a31fe5858cf73be
SHA256:56c428a1e1cd3f3708955e2c913e8473dea59de5b6cd43c8c107e03ff7492a12
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: index.BxQ34UMZ.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/vite/traceViewer/index.BxQ34UMZ.js
MD5: b839ab0efa623b70acb377c6029db3ee
SHA1: 7e4ddbc52157aa8cf59619260abc3f722682c2cd
SHA256:d001af7fd4bf3b8520f37456211a498e655257d6c6fa6a612934fabac6342cbc
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: index.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/index.js
MD5: 3cd60922c3c85d3aa962d0f32072c4d7
SHA1: 1673a70857a48849ce20d0ec300d9b076f25275a
SHA256:a4f83b5b2915b43bddd5384d963a66d1fd4d978a3db8059969fb78de65bc519a
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: index.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/index.js
MD5: 6c96a7dcda321fcd87d6bbd27e5abb47
SHA1: 8e313174bfc682732ac243d7658107ad172b05e1
SHA256:0fca958ba03b99078f318c7b6e9c7940427f369137ae96baf204679fcff0ec80
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: index.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/registry/index.js
MD5: f1023dbf89d0fd8ef3d0ec468e5e87e4
SHA1: 82e2d3391e18492adbb7147dd32ecd41075f8d98
SHA256:8fe9789552e208e65152e31950b6a18fc3db6e177280af90ebac8f8a3274150c
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: index.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/utilsBundleImpl/index.js
MD5: 875fe716891ff784c0dde8118fdac4fc
SHA1: 34de4786cd82c83c9b6a650b2394afb90ba6b97b
SHA256:d1c838d1cce44a1fe36b28fee2eb29ed20daca1de44d3065f476cb31f245a505
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: injectedScriptSource.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/generated/injectedScriptSource.js
MD5: 40b0b8d10afc993734b3f416b7a8eb67
SHA1: 62006855f1c04a93de96a8c3083118f26ad2d910
SHA256:17f415019175f56bcf5e8e62155eaafbf580d89e48647ee40be405da1bba0732
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: inprocess.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/inprocess.js
MD5: c8ebfebef3aa6fc70dc3ccea9126210a
SHA1: 480456885aa818b970ebc8a3bec50708f6c5a3a9
SHA256:edd68f73a21a646edaf8af34714cfab01598763c446590e0070fb2efbfc3a8d9
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: input.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/input.js
MD5: 9f7c03c94d46310f7b10afeaba205fa8
SHA1: f7df79a84ae3ba8737a6d426956a7fd928a9d65b
SHA256:d590372703575ba281e1e4f0652d857aec5f7b95ce2376ae98130789ff5e0353
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: input.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/input.js
MD5: eadceaaf8421b9cb3b4794b7d0c86876
SHA1: 37641b4952a5f334afe666815d1701c15e839719
SHA256:9bab3cbf128c2338d3eee76996ea9cd7044d27cd9b0c6bf7b1786669354e9d1a
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: instrumentation.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/instrumentation.js
MD5: fbeab771c707b0620581e0edfd7e0eda
SHA1: 6a3e66291fe5db1572db911e4151e7f898e9c4c1
SHA256:22fa865e1142f16e638600d3d3eda4677d340fed04e090e1ecfcea8c655d9b8a
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: java.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/codegen/java.js
MD5: ee3b78e955b0b7a7097c1491b4a54048
SHA1: c760a57c0ebfbc6229d23300d39bd3acda93c844
SHA256:f5602fcfcf73f66c54ab32cbb1a593b670f47da11abf6d4a26e00d3ac8a5943c
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: javascript.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/codegen/javascript.js
MD5: 83157c2cc635ff49053da9bda8077044
SHA1: 76679d77f05f8983ff99724cc72767c388f2fca7
SHA256:28ab28ffbbcc2cf55206e7d6a9b7ff4f7f9ace13610dfcccb55b8929c1794304
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: javascript.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/javascript.js
MD5: 55df9582c9491b2d5dd62512dac97b0c
SHA1: bb1c54bb18c760e7df105879e1ebfc6a540723a4
SHA256:134f2aae953ca802c3d8c4da2ddb0857129ae3044f8958cdb857993341aec257
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: jsHandle.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/jsHandle.js
MD5: 1d1c881112d8e75f953d5aec80e5c5c3
SHA1: 877707750e59e2b80f7b2931b89bd34f3857d2c4
SHA256:473be495eee4daf8942798fe1007f40992411965363db9109eff7fbc7e950416
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: jsHandleDispatcher.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/dispatchers/jsHandleDispatcher.js
MD5: 7b4d676e2ce985480cce5bb507ab8260
SHA1: 990c30649ad3e40423846e5eb4b15615ffed26ac
SHA256:750f3fff764f517913a90e61e04b000a7d777e4ef947fca5bc03b43b8ff70c74
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: jsonPipe.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/jsonPipe.js
MD5: a37b6f8ab4de161751c7a966651e0ff6
SHA1: 3019b9731d04e33a6af2a34b83b4669ac462c7b3
SHA256:4cddb6608f39eb8f3e33b3db894015b1be4aed20d9cd908c6042efbd0afe9e40
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: jsonPipeDispatcher.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/dispatchers/jsonPipeDispatcher.js
MD5: 80de6aea38b2ef79f9d5c3463dff22d0
SHA1: cc95b38cad5a60b7f3d588dcf4a0f335233d47fe
SHA256:da633da72760ed6af4bb16543fc7be5367e2fbc3a4bec403ed435011bb0df7e2
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: jsonl.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/codegen/jsonl.js
MD5: b3d4dfe59685ded6fc2847b758756ab2
SHA1: d5695fddc54d0e3b0ac221bd8472aa7babbea12b
SHA256:823edb38c5b9804e51c4e8df1d42cea79332b4664d5c1b7704d6f0317775d47b
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: language.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/codegen/language.js
MD5: 44abfbf2b4e36f0b47b596a413296b1d
SHA1: 155e7b16bfec1a64523fbcedc9e76edb0f588432
SHA256:2b474f802c0c65ff2b30403962e3ffea6d7eac4ec46d2a899bf5bd13a20a1ca9
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: languages.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/codegen/languages.js
MD5: 947ce2af40116987c20eb73f8b7e5cfe
SHA1: e9068605c932ba84809a8cc56960ca1bf53d84d7
SHA256:983e97d682bbfa9f60e23a9f4865112a91cbd21d8823cf079a1290cc55e58165
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: launchApp.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/launchApp.js
MD5: d1db5cc29c9668b11b2f5c5f81815345
SHA1: f6aef9a475878a67807207bc1a72c761464ab5b8
SHA256:523ebb02ea8c2368c3120b82124a4db28dd9fe79a6a19da175bb5d703e13b29b
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: linuxUtils.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/utils/linuxUtils.js
MD5: 5419310673938c6af166362e4e87bff4
SHA1: c840ff5edd7dd31642eb528dcb6db3c66b0ddce5
SHA256:4f507e66ec0bc8bf63d494d5d2bf1633691c7434483912507e7a5eb9337a50bd
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: loader.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/electron/loader.js
MD5: af7ad3738eb7b896581ef354c1db73bd
SHA1: 452f81dafbb9fc86907c52762dd98ebf53370587
SHA256:f92981c101d9d2b137f545e8aff1fbfedad7f65bbf69747ed6087c691b18898d
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: localUtils.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/localUtils.js
MD5: 5ea918bcbb08ac97fd3de753e2258637
SHA1: 6734185441b973c2e1560df4c6a273f10ebb2d45
SHA256:cd64b11c889400f8446ead1cff8d91c1ddae2c2224436aa6df56d4bc849de00c
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: localUtils.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/localUtils.js
MD5: ec1dd1efc3d29d21b5a4eb6ef8dd70f0
SHA1: 589a0d7b1660af015bf90b1807d88f63f673db74
SHA256:9c08f299a6e763b8d55ad5e58a644e9f4b08dc994d439804bb9b0ca7dd7f33a0
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: localUtilsDispatcher.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/dispatchers/localUtilsDispatcher.js
MD5: 7e1c2dd3ff6f1ea30d45e5a12e273b4e
SHA1: 9b2c7d31ff7b4a7159a72de1cefe4b11c363d942
SHA256:7b036251d665842fb1f6af7cd975512c6d17482bf4e4bf6c28f88fd8cb5ea248
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: locator.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/locator.js
MD5: 9962a1013e60d2d2a8289e57735a8229
SHA1: 1a2f1040aafc800da47f443cdc42ed764cf00d53
SHA256:9c4fa569fd160b2f5a3204615967499f925deca68fc6846af13e0cdbfde87135
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: locatorGenerators.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/utils/isomorphic/locatorGenerators.js
MD5: e00f08f34241d20afd7ed95026a8be6c
SHA1: baa46a61ad20e2ce20f74ad5c4bac5eb11d02263
SHA256:6821d0569a9cead7a7d356d70f4d4531182178cd7616277d68c778874aa95ca3
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: locatorParser.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/utils/isomorphic/locatorParser.js
MD5: 8777711a156d62c0e4909ceb993425d8
SHA1: d42777a4fb2114e4d016c003ae6ee196f229d182
SHA256:19039d596a64ce77e62f0cace1ca3411946c68834a165914a610e589dad1e007
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: locatorUtils.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/utils/isomorphic/locatorUtils.js
MD5: b79f94579cb9976ab480038392d7ca1f
SHA1: 015e8948ef9891c465a286766af22ac8056daee0
SHA256:a82004d8937628c05bec84c61f245d7d027624b58c08abf91ed2319e63742670
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: macEditingCommands.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/macEditingCommands.js
MD5: 846bd697140ecf0df9d3f6be7f1347b1
SHA1: bfbe0eea9548ee37bc4291a062ff1d4ff4f1241c
SHA256:ed19a42c03283c800f5d80bf7afd72c927a726cd25b639e6092e08ba7e2da7b1
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: manualPromise.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/utils/isomorphic/manualPromise.js
MD5: 53628279ae4204b2c2a90e8e1d83474c
SHA1: 6bdf78c86eb9d91aecc6fee5051fc976a85d8d8e
SHA256:941649e4378c7acf507ba9fb87002715cd43bda58359edc827434c09cb48060f
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: mimeType.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/utils/isomorphic/mimeType.js
MD5: d834165fc89e28649734ab98e41a0e46
SHA1: cab345666f190906cdf4c5c4d5c4a1b11cae9c9a
SHA256:9286025386f8c41bcbbeb3ffa1fdc6e2fc3737c339aa44a6b419095079714631
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: multimap.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/utils/isomorphic/multimap.js
MD5: ebee54d5e03c4f3800917e3fb65f0d39
SHA1: 68bc1ba02c1b6063d8b10c2592fa928d60f03e73
SHA256:eb2840c1182931cfb3bfb62ce4817003c52d3642e05d17fe02fc54f462cd25c0
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: nativeDeps.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/registry/nativeDeps.js
MD5: d62e8adec1d3d71fdf8f9f2dbf4233ca
SHA1: ac9ad65d920038bcfa857d262091e66614a9e5d3
SHA256:9d3adab0fedfc5f6c48217582fe34624875dad22b3537925bc6f81140c94ed6a
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: network.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/network.js
MD5: 764dd19360a9cdd1e82d3486d172a61d
SHA1: 179be019f470296465ce2d2f80b2ce3a91c4c4f5
SHA256:385cd7a58fea3cf46d82533b7c041eee41c903cf9179a810da11f4953df4d9e3
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: network.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/network.js
MD5: 21ff751d48b6cb95d12c7a425271d218
SHA1: 487d6272503e3670175686422e13bc1fc459f693
SHA256:6405362d8778d46d0aa64332139927cfbad311fdf915cf2284bf05ea8cd05e48
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: network.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/utils/network.js
MD5: e031abd53fe819945cfe8b1dba5d0cca
SHA1: 1384fa9baecac53c05ccc59857837002b32150c6
SHA256:9a88d84ec77070487b0548107c4ce1fec919e6c87658d5cd87bc17c50e07be89
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: networkDispatchers.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/dispatchers/networkDispatchers.js
MD5: eb5e2c13903ca671627a02592c1fd14d
SHA1: b26c0ad04a253e5ebd8e0645a1236ef958103ab7
SHA256:2cfe9170ee8a1519166bc3da8138b7b711518253a0fae2ca750a8228aac643cf
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: nodePlatform.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/utils/nodePlatform.js
MD5: 87bd202f5100f0974a34f79e543ebf08
SHA1: c1c2932d6e879fdaea6aa6893912e27c7a55f0bf
SHA256:2d070b77ee2b66a5e7901d800561ebc067e407f53012b60c63ce01e36e792d8c
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: oopDownloadBrowserMain.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/registry/oopDownloadBrowserMain.js
MD5: b5d1ea26153002617fafa96e6297d568
SHA1: 7c16410fa9905314f2c20aa9b2414de97b085ee9
SHA256:51d894c4ebdcf6b10ca6ac40c57a939c7cd4fc6fb49df78b8767788f3bfd1cae
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: outofprocess.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/outofprocess.js
MD5: 770933177ea66e7dba2abcb0cef50d6e
SHA1: dd051e106a00c9030ef6e4201d635c646a508512
SHA256:72af122d479e3d7f6eb6b8950825a3b2be5c7f9451c7f08754912da9723fd3e2
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: package.json

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/package.json
MD5: 3cb094fc0344bbab4c1158958e5aa37e
SHA1: e5c43eb6fde7c8a2a6ec79b340d2f6ba84d027b8
SHA256:a4af52b0d7e40454bb7ec74fdb3b557219c1b243d061eadf59eb4b3cec6b0cf9
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: page.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/page.js
MD5: 08423407bd2c50be89368c8848457b24
SHA1: 4c97f2545d2f292ecba5eaa54d20ff43985562e5
SHA256:a117fd593e75cf2088921a834fcebba3915323952635ac5d1bdb1c89ca42223c
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: page.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/page.js
MD5: d2410620a72d7128b59abf4f8ae9fa56
SHA1: d29c8a1656b6cd8b03fb72c026b423f655b995fa
SHA256:1837b232c356095f405b25a836031737fb7646247aae8e033c62dd861d2a345a
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: pageDispatcher.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/dispatchers/pageDispatcher.js
MD5: 54bcfb089110f6d2e2b41cdc14d62fb1
SHA1: 2052c981b241510d1934d16e7aacf62178713a4a
SHA256:0bdc3bf905635f44f804a272592bd59704e275ce7a71af6665e1ab0cae729d32
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: pipeTransport.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/pipeTransport.js
MD5: 10a4559516ab1480d61efbcf75ba1572
SHA1: ff7d8a054ff88ea4e3cdaf24e928bf7937c6b881
SHA256:9ab01b72ead31eb7a07a439bc983d6e1738dd876dac7ec7a4e205d23563293c4
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: pipeTransport.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/utils/pipeTransport.js
MD5: 09674176aedad9871b1f1e9fe7c216cd
SHA1: f8a0d4dc3ba3f605171952a76138a48eaec0fbcd
SHA256:0f3d17e585ab0551a0b3f34c5cc54415b9cf52d7c81b43a3ee68039b3fe95dab
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: pixelmatch.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/third_party/pixelmatch.js
MD5: fac449d46888a94e6b22fd3e9180b505
SHA1: ff7d3e8e93923bf282f8728a0ca58d3eafa6ea29
SHA256:7383ae817a69534f6e6729e654f7013c54cb863b0e2c65465213f3de83c327f6
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: platform.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/platform.js
MD5: 9c841e298433e7c38a3c40e347b4218a
SHA1: 0053cdc6d35501d9fadfe6afaa6de763d56e2f58
SHA256:f382489c5604ff1374cd01b5b6c73756d773e14607dee58686b8368b96f868db
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: playwright.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/playwright.js
MD5: aa791b3e083ea980fa132ca94717918b
SHA1: 11be7e61e0512c949506bc3ff5d3081f35853e9f
SHA256:e0674a5c72654b25d716aa7130c878b588f89e0f59b8476496e76e351618ba94
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: playwright.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/playwright.js
MD5: 05aeaebe61e73b1d05e0817dff712d4b
SHA1: 25ce5c24c47b3ca0e8e75a96628fa8b02d2ae011
SHA256:ef391cb7c445bb8174df3feecb315987d21bb9e4966fbd56c62b8658fabc9841
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: playwrightConnection.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/remote/playwrightConnection.js
MD5: 7beb2bdf180b15a226c6a8c44502b349
SHA1: 2f9186f3dfb124db50898d9f2d2bf3d06b8c7f9a
SHA256:a5f44b644efc49cfc9c8d308dd6be0fa039cd3c2f4cc9bb326e95482802a0987
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: playwrightDispatcher.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/dispatchers/playwrightDispatcher.js
MD5: 9dcd073b3447fbf7609c558dc5d2ffd6
SHA1: 067c106205d98c677cca970fe23b91e715b47580
SHA256:0105dbd04d075ba0e12abae7ce7b463538a9b2f70ce3040b815488d9ed66a0b9
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: playwrightServer.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/remote/playwrightServer.js
MD5: 68edb1f7b4db4399c50f95653a0daeea
SHA1: fbcf19db9303cc1e1466902d61e02836b21a7152
SHA256:d564bae126a7467c9fc5f49e616bcad8ee6423222a96832ed43d58f9c6a58fae
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: pollingRecorderSource.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/generated/pollingRecorderSource.js
MD5: 34d7c1c3afaaf196c188a454273989f6
SHA1: de329bd8123bd35005cbf30008bf511a03ec7863
SHA256:406cccff10249211dc32f2982a34a75aa642b6321e3f23d5311b01dc346b62bf
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: processLauncher.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/utils/processLauncher.js
MD5: a7ce19b24cb5d74299c6751b6d94995a
SHA1: 7f77ef4a8d1a0ad991b7b42481a7f819ab0471db
SHA256:da9cb41cc1605fca1e26c6a6212f01ef0af0125a9e97eecb70671bb3a8f1fd07
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: profiler.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/utils/profiler.js
MD5: 18372902052430ca0a97184207a2dd10
SHA1: f04bb738ff6131f22d10c70e7a2b98e72c078f57
SHA256:449487e915ff08ff60642e3e8a01067960985adc201573d8608e44ec7fc0d4e7
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: program.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/cli/program.js
MD5: 263d08a84b38ddd814874fbbb232646f
SHA1: 9b09c64cc22ea15aff527da7c25b811607632450
SHA256:e2915a90f3a86d0fb19739fe2042f7e95cdfa5dd08b8a2c7997893780b635089
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: programWithTestStub.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/cli/programWithTestStub.js
MD5: c451af0022452d8e681ba0a6cc6bc219
SHA1: 556f4c87a1cb2b8506a0128a6789096cd31b665f
SHA256:65b7251f44d41bcb1f742716d70a7ee1edb7fc3a2b8c9b7244f68e804184fd88
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: progress.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/progress.js
MD5: 16c664f210e8f008b61c6dd786bf0677
SHA1: 0d53525403205974b4de3092778de115f5a38319
SHA256:49004f90a702b25828fc6baaabf9357b60836df4cfb5b6a52ed6271f81e56517
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: protocol.d.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/chromium/protocol.d.js
MD5: 80caf7835f7af181789664cf55f7d58e
SHA1: e61b06432e370a586ef1fd7e624569e6d4af9727
SHA256:6b7467f93c2627e3833867266eca9c25639231878e0544a2dd08c23e2ad07ff6
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: protocolError.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/protocolError.js
MD5: da20a44952dfb280950ed04b56978b8d
SHA1: 03219faef7c04b74a398c81855a210478e94ce68
SHA256:2b6d9bd97aaa6ab39b66968aaa734bc5c1520f38b3820e0d481f2a18063dea3d
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: protocolFormatter.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/utils/isomorphic/protocolFormatter.js
MD5: fe92acd7c54aa4cc39b1ee9e873f2dad
SHA1: e7d544595434f74f88c762488c376d0fece524ea
SHA256:b7a554306caaaa94a99ea9d127c6718d44d2fb8ab61e6a2c57cf4285650e2e3e
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: protocolMetainfo.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/utils/isomorphic/protocolMetainfo.js
MD5: db5db9498aee61443cd5e51d28190d7c
SHA1: fce490917d51b78b39413ccb6cc44454ccac2058
SHA256:421fca57fb2eef1d618d59bb3c36fd41099dda74e59e472e11aed04016556dcc
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: python.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/codegen/python.js
MD5: 2d288fa0d644436da5779d0600363623
SHA1: 580d10fa554a9d23f9c7405d3a5f44f5670287ba
SHA256:b94d0de4b61422f86d688b65645b9593109cdeeed1d39bd1218117f75ba18393
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: recorder.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/recorder.js
MD5: fe3dd4d7c689ea54b260ed325a555ea9
SHA1: b202489828f80944686bbbbec43110a1587a005f
SHA256:204aae1ef479c47f13d816a2177e91608ac5227acfa9add1fb57592f547c2aa7
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: recorderApp.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/recorder/recorderApp.js
MD5: ea11620f0229121d7ee329c8bdb5d092
SHA1: f0d4ccccdd5e4b2367629933f64a1ab448e9595e
SHA256:40fe5c9d401f44cc7f066157aab52f1e49a418dc928ee30ca49442bf019740c1
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: recorderRunner.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/recorder/recorderRunner.js
MD5: 3841a9b583c550e287e9fc4b56fcdd4f
SHA1: 810ccb524fb65fd49eb9f306d05c8134c316d813
SHA256:d23a6c081a874fa83f199cbc1c201fe97f6d998982e76ee68e48cd4732baacca
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: recorderSignalProcessor.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/recorder/recorderSignalProcessor.js
MD5: c455605320f3c013a6ef089fa1799119
SHA1: db47c7bb2cde69eacd308e593988e96c3259b227
SHA256:7911eec57ca89d252f8177cfd916a79e52bb17ccd58eb71f02a6502525ef1a2a
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: recorderUtils.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/recorder/recorderUtils.js
MD5: 5919794a6ccef5f1506451a95fccd789
SHA1: 626e7bad27312001eb0638f6fec8882236a16c89
SHA256:c7e93d651108cc86f0836e6dc7acd7f560505f15f9ccb8fec8c53772e3ac0715
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: rtti.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/utils/isomorphic/rtti.js
MD5: 2cca5300c21206c26d16d83b9c418e09
SHA1: eb725f3ba620cc3f47aff487c8522ffcf4af23cc
SHA256:e376d934dfff437be1ffc3e8f23eed0e4ea4a27f2e2e3a0b0df288ec54bdd765
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: screenshotter.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/screenshotter.js
MD5: 2a4e5b1053bc82d4058ee81887676511
SHA1: 120feb4e5ec70efa82dd84e4ed8cb5247037c5ca
SHA256:9aaff6c173c6a9a1c80e831dd92ccc24097243d49ad600dc87c4bc1fad9c625b
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: selectorParser.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/utils/isomorphic/selectorParser.js
MD5: ae363c55cbc5ec140dee103c2c2e0ef4
SHA1: 2ad04abb6be5e99c9a037bf0ce5ab102913dbe86
SHA256:6205503cbc67a66e548b996859758ded44f63a0ece91b2c9dff5807f66a9b4cb
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: selectors.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/selectors.js
MD5: b543d562b751cfedab5e47539f8eab81
SHA1: da9bea6336ca3178e9ba39afd9c17be1a02fa528
SHA256:ebdb098e84de852a5b64553182ce41d4de9d19f3421f554107028764d9638850
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: selectors.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/selectors.js
MD5: c803803608b1ec356177578aae6ab48f
SHA1: 959f26caa640d8b695584180d751f2714cb1b03d
SHA256:b2edcf2a1cf2a04e82de47df2e1e5807c7342f38516a4c963afff0194a54b897
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: semaphore.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/utils/isomorphic/semaphore.js
MD5: 875643e394565f944eb8c4edf7e410cd
SHA1: 5be69cff000acea441a329ba3cbb676075729e03
SHA256:39623fdc9444c0a8c9efe5d86e6c5d4d854e13b2579e884e63f390cce596e790
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: serializers.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/protocol/serializers.js
MD5: 2c957037440abbad44a653c502c6c88f
SHA1: 79638fcbbda12158ead70d085933115e5783d330
SHA256:ba7df6ec4f703f205c75b18a07920def33f2a69ef42091a9b8ce23e2297a3de7
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: snapshotter.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/trace/recorder/snapshotter.js
MD5: afd2bf0b5e654ccded0016d31e23cd42
SHA1: b0156f372aa19747c998b2c5fab970f9ccc8aefd
SHA256:3dc3f996abc0201edf6b254b0943efefcdc516ec9c6661d45cf587285e72702f
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: snapshotterInjected.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/trace/recorder/snapshotterInjected.js
MD5: faa2cafbc71f5a7d97fba7b0022173d0
SHA1: 7e08db978c7b7ceb6b455689e767901660059ffb
SHA256:2b4f6d41bdbb2496aad31bff0d830dfb1b045d60e3a5fa442d71ebfc2ab2288e
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: socksClientCertificatesInterceptor.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/socksClientCertificatesInterceptor.js
MD5: 50f197c8e80c09819eefea62f635242f
SHA1: 2f8327f892e12e718df0c958f0ec8b5d94bebe5d
SHA256:efa8de1d21be81f9e27515de9abb0d507e5269341d0cc14d722fa3df0d97c2a9
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: socksInterceptor.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/socksInterceptor.js
MD5: db94f6e758fe0df0907c94aac2388b71
SHA1: 362d228e7fda1ec0a4c667675ff29aaa6318a22d
SHA256:3ade31d7175b24336af1be1065d2e7b8f1a44c78b9b98ee55f2fd3391c1afffc
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: socksProxy.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/utils/socksProxy.js
MD5: c0e382969d7128ec3e8fa05bcbdc66c7
SHA1: ec2da21f331e3784f995f7c3495be9f2746ab855
SHA256:504def4ec741feedeccac03f08dfee735686c7f4846f110fb7563aa83d63bd99
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: spawnAsync.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/utils/spawnAsync.js
MD5: ea3ec5d0eabc1475824462704b7f83bc
SHA1: bc615c28e5975f8345335cafc1ac4284d28cca15
SHA256:217bb7d22c0b8a73ba06d8cd42bc55a443c2089db353d9fa80e284f6fd03944c
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: stackTrace.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/utils/isomorphic/stackTrace.js
MD5: dbb89574392241af8d0f96a19460feca
SHA1: aad06303a57d8561b220975b5dcdb1cec811e484
SHA256:ed6e3bd91d339584f7b3dc207c66de9e4fcf5cd3a76b7691828e489ac59397ea
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: stats.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/utils/image_tools/stats.js
MD5: f5871d029b37dd13024c320c89098612
SHA1: a1915894df811119bc1ce838bb97a906f7fcc4f4
SHA256:5f4acfe8490fd1c7a8569274e2812f4bbc1adfa800647517e5c01c11c3ac95a0
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: storageScriptSource.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/generated/storageScriptSource.js
MD5: 9f46896fff03d26551e02b3ebdd2ae12
SHA1: 9e97cfbb02183366232be811737e066b9edffd47
SHA256:e8a1133e3d51c03fd29d773693db051ce94dfd7ef83e53530bfb936bc871ef20
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: stream.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/stream.js
MD5: 1099144e0018753f8c665e9c47dfaf71
SHA1: 2121f5549d6d6106517f73290f822013cd1e76aa
SHA256:04b3d600ed3ad591e46ec6b4ec71dfde90cf64d07767dd0cf9e6cf8308271ee1
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: streamDispatcher.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/dispatchers/streamDispatcher.js
MD5: 304486f352a9860085a035d5a84f820f
SHA1: 15e080784f996a97850f55971f6dc2ac35b506c1
SHA256:28cc8af93733615527b421bf7aed0ead37fe6803f20866b1e087040fb8c6b764
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: stringUtils.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/utils/isomorphic/stringUtils.js
MD5: 0ea7a78e377114446ecc6b2d910aa756
SHA1: c6a924469a259f851f559345b97850aca92fbc3f
SHA256:49408bb3f029dd904f9cc0ed74753e9a89ef18797b7899e9356cebf44d978bcb
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: sw.bundle.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/vite/traceViewer/sw.bundle.js
MD5: a336fbab55ca96cd4069e1b50128eace
SHA1: 871dfcc53ba60473e64bde3134832049ee4b6c33
SHA256:de39a53b34100a5bbb01f35ce5970ffd3e2dafaa727f9536c8c92c2f563185ab
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: task.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/utils/task.js
MD5: afdfb62fa3aebb71931986e047ff96f9
SHA1: a707039ee0fd303ae0aac8316ad74ab439deabb4
SHA256:957a25d42b68fe708b30f27f57cd0333a978591f0a1aae13378a921d929ea92a
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: throttledFile.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/recorder/throttledFile.js
MD5: 6685e960888a569487d3fdeedd5c9686
SHA1: e64258363048a5b24799ae29ed4fe32d91fbfafb
SHA256:75f1dc25dc7c07ffbacbe85b5bcccc56fd81d10140b2bc6efd42710b205e3e89
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: time.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/utils/isomorphic/time.js
MD5: 82bf332375d5f59ed3a9151db0b01002
SHA1: c8b665577825663651dd1a953362f122c857baba
SHA256:0eebe61ffd113084f595545209536b7b354bff04faa0f8a7e0ab29ebc5fcc179
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: timeoutRunner.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/utils/isomorphic/timeoutRunner.js
MD5: 8ba7e27b4d28ec5a62374dd99e55ca61
SHA1: 48f7c799581a2b20579019f28f60672085951a6a
SHA256:614259ae1c7e2e0edb1e8c22176f2872de9aac4682b22be1d611dbe3bd3b9720
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: timeoutSettings.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/timeoutSettings.js
MD5: 9bd83625d79201acf3089911c7d85293
SHA1: bed614237388c43cfe038a1f1788d411e445c873
SHA256:3049c9c53cb5c4f84d0fd00d237c2f78ddb70b8ac60908790b8ef28eb0b14ef0
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: traceUtils.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/utils/isomorphic/traceUtils.js
MD5: a7502d0783515079fdfc0325c90b9053
SHA1: 6bb597c52e622b22e663ebb869e6eca8073e0cea
SHA256:c291f5bd2d74a85ffe088abae4eb582a460508ed5d2ddacc1a48fb6f64f9f07b
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: traceViewer.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/trace/viewer/traceViewer.js
MD5: 78261305c49463ad295c5c77a20280be
SHA1: c92afc2f9344806319b22c9c399ac69a4ba1d33b
SHA256:afbe19a29e778192dfda5dd400bad8c55262939960d0501f0dcf9cb2c2af2b4d
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: tracing.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/tracing.js
MD5: 45ebf7bc49a5d949e93ec8c8dc6faace
SHA1: 5d4bf192bbf380bf9758bb7faa4c4dad914e45ce
SHA256:337a43b0ef24664069724ccd28198b3f5ef5bc1da9b7c1fa05d1e0b4e517a1f5
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: tracing.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/trace/recorder/tracing.js
MD5: ee457ec3628f21d8d78bf138935d968b
SHA1: 435fe48d9739d002d2f68c9b478e12a4bc6b3f32
SHA256:9c132491e8feff7795bc599074d0ee62cbfaf0c9d05f80d852ae9b7376c58942
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: tracingDispatcher.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/dispatchers/tracingDispatcher.js
MD5: 485f3f5aa3278e943814884f92ace970
SHA1: 913b83a95aa3bf6950eb51a009a603b145dfeb76
SHA256:d33e000446bef59df7e5f580bac29247309974dac3543da0fc562f5de85a85b5
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: transport.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/transport.js
MD5: 8c3e1c9534262babbc16e6f67c5e2d48
SHA1: fb085a987e6f5b497b0d970998f6b38e22220cee
SHA256:2b06df2a0ef2340852b693ef5bba3b98f8a988cbde5dfd0d6e6ad62e08e25276
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: types.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/types.js
MD5: 9cb9240676bc76137e8d6f4aed21f462
SHA1: d167223162ec6298bdcd278d13e5c629b0b360f6
SHA256:8daa2915fbdf51c6e3a08e0e4d808d672bdb5166f719a9157c343e64d87550cc
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: types.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/codegen/types.js
MD5: 9e17e684e49336d6627dc202ebc1cb15
SHA1: ac2a1790001ad78230a2da12e13c6a614975e66b
SHA256:4e4d8fa8a86983748bad7e158d3e58b2ba98806699a7fb66d04a644b7ae01e45
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: uiMode.BWTwXl41.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/vite/traceViewer/uiMode.BWTwXl41.js
MD5: 73b3cd153576ac3e0c49dd7acaba44bf
SHA1: 88b90bf9c249d026ee34faeef70b8850e2a43854
SHA256:af19fd578c2678972e847a36c819fb1eb0b4cddcc813e5de2c7013d6287b717f
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: urlMatch.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/utils/isomorphic/urlMatch.js
MD5: fd3bc293c160f5a2dddf28bdc8c90e80
SHA1: 2b5f50695f6150e2a1e59953d75a90cfb0e1e3d0
SHA256:d612c86ca0ead7d61797966aac91c958fa6100f83026be963aeea3da713a7e3b
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: usKeyboardLayout.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/usKeyboardLayout.js
MD5: 9c150065641041ceb92ff91a75a08433
SHA1: 954596b95bdee1fe1d6f0cb649bb3f505380923a
SHA256:d0c424c2856f64c1abfafb1b01985e32c027c364d41af29519a891a1b5ec4ed0
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: userAgent.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/utils/userAgent.js
MD5: 9e219a73f3ae9abb3980184b6cd00dca
SHA1: 289a9c48db4e575c507d669675d6044c9f012601
SHA256:99dc708b2ea62c14e7e18415a8223262becd1e77b9abcbc9a14f740f51ce9635
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: utilityScriptSerializers.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/utils/isomorphic/utilityScriptSerializers.js
MD5: d3972bca32a1404135388522b782b664
SHA1: 00ebef6805e5e72aec8a8121a374a14e617ad014
SHA256:5dcac17c30fe7d83c7b279b4293dc624d42fb9cc269bd5e4187183e32f41508b
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: utilityScriptSource.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/generated/utilityScriptSource.js
MD5: 1c72ce94b7598c128bc2d5d95552efa7
SHA1: 677177ec4a4f43103cf39defb27dda3985081db7
SHA256:6706bdf9fc43d4573e14f456fbc541858a4acf89e3e43c7dea9ff455bd276af6
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: utils.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/utils.js
MD5: 20da84ec2d81f8fc3306830b45e4a296
SHA1: 938bb0c611ff3e221e9c838347b68b4b3fc18926
SHA256:d69269e5078edb372dafc5b2deaca4f883d4d7f0807bab91e6da72cfbe2359e5
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: utilsBundle.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/utilsBundle.js
MD5: 34af0e8dde214357e1a11c4ff5e7d08e
SHA1: f1a632671cbcc5c125474b6cd2e92b357ab5846b
SHA256:6883cf83e2097e5029cce0763832338534a9e1c8e97bf62ca2f083b238613a49
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: validator.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/protocol/validator.js
MD5: 2b7a1cd4aa51f848536fe4cf662a2fbb
SHA1: ae58248388b730d10c5afe1cd2cbf23577ec6fd0
SHA256:2a563048cf056966f2ce34fc9fdb73ee6aa3e411131cf01ff56918dfe6390ef8
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: validatorPrimitives.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/protocol/validatorPrimitives.js
MD5: ed019841865b3ca9dc28750813b80c4d
SHA1: e29d6594dc252e8b634e9404829f70bc14aa7c52
SHA256:a3abe78847253497de04ea6f329a925df66c9a2dd62a5830aacaf1461d4128b3
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: video.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/video.js
MD5: 384e5ec8eb87bafc7a6ef7d67e813a99
SHA1: 2a3776eb8e6581c9dd0143bb44773eb19c31c418
SHA256:5370019ba5b7d9d0e2ec22e24c1275f44e02f063e2f7a9604a067712413287a6
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: videoRecorder.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/chromium/videoRecorder.js
MD5: 88fb2c6919695b3002111e20cb3dbe52
SHA1: b1ad1f2032bf5be51f027149ce0439a1bb9e16e8
SHA256:db8da9c037d5fa90a94ea5573a24b88a4a3edb00217b01f2c7cbdc46357658ba
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: waiter.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/waiter.js
MD5: be30836298666c6566179df451ae23de
SHA1: 43dae6e47a241d6987b077f7a0b06e630476418a
SHA256:3b060a8254cdb6fa35b09379ad0a8de906ffa682670be339207d57736bc9f562
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: webError.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/webError.js
MD5: ecd36d4f128f9be3a5ae08890329838d
SHA1: b894a7e1309a3fb36ecaa9fab32f384aa6f93d6f
SHA256:7ed3830da0b42ef8c3cf22fa1872d43449c6cb51e166feebdd0cfc323dcc04eb
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: webSocket.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/webSocket.js
MD5: af704154f4ba0378adc30b4fd1a5cf11
SHA1: 7883a017b50325efeaf372197b665bb2a92ad0fa
SHA256:e7fb652df9909cf11304b056c151450d1630635b834d47f90682eac4a4a75cba
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: webSocketMockSource.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/generated/webSocketMockSource.js
MD5: 21a5ae67ee4aa09e53a3d91c569aa369
SHA1: 733c9f63832e6d62a3b3d60941d4048e4f2ccf47
SHA256:9f3f74d671223b5b312083670f686c7b23948a8cc47de14fc4f303a75d019375
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: webSocketRouteDispatcher.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/dispatchers/webSocketRouteDispatcher.js
MD5: 4c8ff68c4ac52786c2e087c1dbc8b6d9
SHA1: 3e6938890f3902f41d5b7149df0f10d6d19699f4
SHA256:a12eae11b70dc583d915d498771a65d617e13a10ea90caca2f7f1b364e13d5ea
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: webkit.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/webkit/webkit.js
MD5: 71cc76dbded65bad8f208a71ecab363a
SHA1: 7b377c34a25325d00c1ecedad23742d39bbed929
SHA256:30547b980f41bfc75fb5293720656a89f3607d7c1438c7783552c0d25fc97965
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: wkBrowser.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/webkit/wkBrowser.js
MD5: 85dca18128f605d541eeec22820c3492
SHA1: 561fe583eeb3623d4f56de4c953f1f0beab836f0
SHA256:db5d06820f78df6011f2ad4b3a4f074ebdb11720fa3f483f984b33764c2ab5d2
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: wkConnection.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/webkit/wkConnection.js
MD5: 7e6e6f578fc6ebc7f08fd4c7a3c80cd0
SHA1: 6236da45a6278b7fd1ea1071e73fdee9b89cbca3
SHA256:4a8fea1d92004216a99fbd8321cb245348a88d5e231f6ac9e6d80b90164a36c1
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: wkExecutionContext.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/webkit/wkExecutionContext.js
MD5: 476a90eab670cfcc26ce2ff9f2cd4c49
SHA1: d974f04702d52bea6fed3872a388c224743493ef
SHA256:04d8f0c073d10678357c1bd50885b13a5ac0434249e8283911e4b8cfddfe53ed
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: wkInput.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/webkit/wkInput.js
MD5: cd1fc639ccc346e162f61da16fd4820f
SHA1: ef807d200214a2de80aa8aaa0bb3d7666adab457
SHA256:7fc2709e6a26e60d005d1458f0df3160f69a7bf7a2db55b739e69222e8ce800e
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: wkInterceptableRequest.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/webkit/wkInterceptableRequest.js
MD5: 71ad0633dbdbaf173112e523c0fc567e
SHA1: 85cb244b91b48c2e67ac63555f0ab76256b1c9ff
SHA256:def517d6a9769e0e9e5d015127d50b83eb150a7d70b3a19893ec08c18dbae044
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: wkPage.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/webkit/wkPage.js
MD5: c5cbce4d0d12fb4a50452c65f98bdd0f
SHA1: b8cb7c2fbc0406f1fde8d79e03ef3925715ef983
SHA256:d607ffc216f2e4dca88900f9371b92e4aae840cef4848811b62e886c8014d348
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: wkProvisionalPage.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/webkit/wkProvisionalPage.js
MD5: 834f0fe9c05de9abd073798caae855de
SHA1: ca3fa218fcea86196e2c9c77281e1959c9688865
SHA256:3c1f7b53ac2391c291e0b2783f19f62f1b9a25d1389a6b587c70884e00df84d6
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: wkWorkers.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/webkit/wkWorkers.js
MD5: 630cd1d47505b94978a4c6dc4e31e5d0
SHA1: 231505736190b804c628b06c4deb414d5d4c5812
SHA256:68f773aa74de0565a31a4122a61df1aca13388bf026fea7f8d6131f97e1ae85f
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: worker.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/worker.js
MD5: 7eb84c2a64a23909af414bcc4f91878a
SHA1: 99f6f2a2d15507108296a535196514f0f0ee33cc
SHA256:4826d37b86fef9ce75f12860717df848058614cf07e86c563919eb8185ce42a2
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: writableStream.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/client/writableStream.js
MD5: 4b45faa9c4d459811538b85409bb1b73
SHA1: 02a5180de8640331f5c5a0f9ca0ad4fbeab02666
SHA256:62d9d8e4be5975d3a1f948a80a99a149351382abc019fc8d5696b1311a107977
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: writableStreamDispatcher.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/dispatchers/writableStreamDispatcher.js
MD5: f7b51782bfc6e17a4f0404cedb9c0cd4
SHA1: 23e16f87d075bda455d0960315ad746061ee57aa
SHA256:40db3a11b797690f9b5f583056ad37f2fec9e70dd1d24584cd28744ad3da20f9
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: wsServer.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/utils/wsServer.js
MD5: be6436237c53a1779a9dece40ae6b900
SHA1: b6b798e391340cc663723acc9dd49d6a8716d310
SHA256:1d109f356be4cda23f284ba053f16fb91087335171e0038ed45849a4aec056c1
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: xtermModule-CsJ4vdCR.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/vite/traceViewer/assets/xtermModule-CsJ4vdCR.js
MD5: 6fd3ee92914ca17710f929cd02c43c66
SHA1: 45ac63f918b6135fef23fe006fc0e137defafea5
SHA256:4aa82b0448cef1cf951bbe0ac80bf2d2b7c5d279dd74bcc798a9e563e98e5295
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: zipBundle.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/zipBundle.js
MD5: fb3c3aaa7d0d23972df3eeecfc26b9b6
SHA1: 32a8c9522024dea3a6fb32508d32b740e006b466
SHA256:90e428a7004452929e811020e788c749aa08132d618ec77759af79c1e4b53536
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: zipBundleImpl.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/zipBundleImpl.js
MD5: 3a75518967d25dba5b975d6595dad3e5
SHA1: 8ba28a17b2244e4f9de8d8e5f23922820014e62f
SHA256:9552c87b175ac3ce5a1eade1e3ebde4e7c2a37031253e4ecabecc51b4a24ddf6
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: zipFile.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/utils/zipFile.js
MD5: 4b6807a7ce91f77c43419a76dedcc943
SHA1: 59a6fc7f33fbc52e1ffd580fd448499edd1e0da0
SHA256:2d7e3104842f03c3569798d34f52ad1a653debdc670302da2d38c68b11659a3e
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

driver-bundle-1.57.0.jar: zones.js

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/driver-bundle/1.57.0/driver-bundle-1.57.0.jar/driver/linux-arm64/package/lib/server/utils/zones.js
MD5: a22a7a55900635a1a3cc3820f5ff894b
SHA1: e1680e0bf989815be0679115590e5f94d3ebd454
SHA256:493b0939e412239080b134e68c4845d625f66ed77b373cc2eb8059b7335c0669
Referenced In Project/Scope: Grouper UI:compile

Identifiers

  • None

edu.internet2.middleware.grouper:grouper:7.0.0-SNAPSHOT

Description:

Internet2 Groups Management Toolkit

License:

Apache 2 http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /var/grouper-docs/git/grouper/grouper/pom.xml

Referenced In Project/Scope: Grouper UI
edu.internet2.middleware.grouper:grouper:7.0.0-SNAPSHOT is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper-ui@7.0.0-SNAPSHOT

Identifiers

edu.internet2.middleware.grouper:grouperClient:7.0.0-SNAPSHOT

Description:

Client for Grouper LDAP and Web Services

License:

Apache 2 http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /var/grouper-docs/git/grouper/grouper-misc/grouperClient/pom.xml

Referenced In Project/Scope: Grouper UI
edu.internet2.middleware.grouper:grouperClient:7.0.0-SNAPSHOT is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper-ui@7.0.0-SNAPSHOT

Identifiers

ehcache-core-2.6.11.jar

Description:

This is the ehcache core module. Pair it with other modules for added functionality.

License:

The Apache Software License, Version 2.0: src/assemble/EHCACHE-CORE-LICENSE.txt
File Path: /home/grprdist/.m2/repository/net/sf/ehcache/ehcache-core/2.6.11/ehcache-core-2.6.11.jar
MD5: 81840aace00ec514154d6dac91ba43e5
SHA1: fae7f84a5ffabe1b814e40190650c0ad5aeda5b1
SHA256:ffe3580aadb6e07f86e49e326f3402fe8dfbf3470eb2782d68507bd31d75af88
Referenced In Project/Scope: Grouper UI:compile
ehcache-core-2.6.11.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

ehcache-core-2.6.11.jar: sizeof-agent.jar

File Path: /home/grprdist/.m2/repository/net/sf/ehcache/ehcache-core/2.6.11/ehcache-core-2.6.11.jar/net/sf/ehcache/pool/sizeof/sizeof-agent.jar
MD5: 5ad919b3ac0516897bdca079c9a222a8
SHA1: e86399a80ae6a6c7a563717eaa0ce9ba4708571c
SHA256:3bcd560ca5f05248db9b689244b043e9c7549e3791281631a64e5dfff15870d2
Referenced In Project/Scope: Grouper UI:compile

Identifiers

error_prone_annotations-2.41.0.jar

Description:

Error Prone is a static analysis tool for Java that catches common programming mistakes at compile-time.

License:

Apache 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/com/google/errorprone/error_prone_annotations/2.41.0/error_prone_annotations-2.41.0.jar
MD5: 75e3b25da8b8a2136463c4674f5e49bf
SHA1: 4381275efdef6ddfae38f002c31e84cd001c97f0
SHA256:a56e782b5b50811ac204073a355a21d915a2107fce13ec711331ad036f660fcc
Referenced In Project/Scope: Grouper UI:compile
error_prone_annotations-2.41.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

flexmark-0.64.8.jar

Description:

Core of flexmark-java (implementation of CommonMark for parsing markdown and rendering to HTML)

File Path: /home/grprdist/.m2/repository/com/vladsch/flexmark/flexmark/0.64.8/flexmark-0.64.8.jar
MD5: 5618d653adfb3db30b81563ce35af337
SHA1: e82621ebed3a6cfa31c52900aaf9a9b6dd3c859d
SHA256:3133878d108f0e1964d7d427f379a7433e1b71a45f9f3c1fab7ed0ac0301d3b0
Referenced In Project/Scope: Grouper UI:compile
flexmark-0.64.8.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

flexmark-ext-emoji-0.64.8.jar

Description:

flexmark-java extension for emoji shortcuts using Emoji-Cheat-Sheet.com http://www.emoji-cheat-sheet.com/

File Path: /home/grprdist/.m2/repository/com/vladsch/flexmark/flexmark-ext-emoji/0.64.8/flexmark-ext-emoji-0.64.8.jar
MD5: 02c70835d4c73921959230233442b0f6
SHA1: eefbf6a1fb644fa14c3fb74017cf9c97a4879a7c
SHA256:012d2db51463afd84702627e493fedce42eb7deb1bae309ddcefd181ab283cbe
Referenced In Project/Scope: Grouper UI:compile
flexmark-ext-emoji-0.64.8.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

flexmark-ext-gfm-strikethrough-0.64.8.jar

Description:

flexmark-java extension for GFM strikethrough using ~~ (GitHub Flavored Markdown)

File Path: /home/grprdist/.m2/repository/com/vladsch/flexmark/flexmark-ext-gfm-strikethrough/0.64.8/flexmark-ext-gfm-strikethrough-0.64.8.jar
MD5: e43b2bedc366c3c43583c74b5ce994df
SHA1: 1851e124c6d85c5c7f3fdbbe066d30a76ad6be44
SHA256:fc6cad026fbd036b3ffd0448264360a5f1b572756ef3427ff022715b7fc5f1c3
Referenced In Project/Scope: Grouper UI:compile
flexmark-ext-gfm-strikethrough-0.64.8.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

flexmark-ext-ins-0.64.8.jar

Description:

flexmark-java extension for ins

File Path: /home/grprdist/.m2/repository/com/vladsch/flexmark/flexmark-ext-ins/0.64.8/flexmark-ext-ins-0.64.8.jar
MD5: 76da792dfba2c39e26bfa78889ae3d77
SHA1: 7d095adeebf934f6424d9444af2ec0b2553fecfd
SHA256:5b61b83c31cb0bd3273cbf12aed3887b63b8bdc6dfa17b03ecf479cf1ce176bd
Referenced In Project/Scope: Grouper UI:compile
flexmark-ext-ins-0.64.8.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

flexmark-ext-superscript-0.64.8.jar

Description:

flexmark-java extension for superscript

File Path: /home/grprdist/.m2/repository/com/vladsch/flexmark/flexmark-ext-superscript/0.64.8/flexmark-ext-superscript-0.64.8.jar
MD5: 001974a85741fa44d033e1a4bd032f1b
SHA1: e5d22f3ec35ac64504cbc238b0f5c63349815a7f
SHA256:457933324d1ca9f283bc15a1842777c6df0385f318fcceade4de41621395e402
Referenced In Project/Scope: Grouper UI:compile
flexmark-ext-superscript-0.64.8.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

flexmark-ext-tables-0.64.8.jar

Description:

flexmark-java extension for tables using "|" pipes with optional column spans and table caption

File Path: /home/grprdist/.m2/repository/com/vladsch/flexmark/flexmark-ext-tables/0.64.8/flexmark-ext-tables-0.64.8.jar
MD5: a123d2a67117cb2fdfffe2b6d9664458
SHA1: 018e37d2e67a346c7c2694dd91944eefd5028608
SHA256:cdf82d26e112e96ade7e370138aeb16920b7e2d411d20c6c15cb1acfacd1ef1f
Referenced In Project/Scope: Grouper UI:compile
flexmark-ext-tables-0.64.8.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

flexmark-ext-wikilink-0.64.8.jar

Description:

flexmark-java extension parsing and rendering wiki links

File Path: /home/grprdist/.m2/repository/com/vladsch/flexmark/flexmark-ext-wikilink/0.64.8/flexmark-ext-wikilink-0.64.8.jar
MD5: 4f8914f1ec907fe8b7922deb53191a9f
SHA1: f443092e4eda97537c449f0ad6c74022f8d5746a
SHA256:f32ef779eefb4c3b80d5bebf3c4b7ad7206fc46e083a5901cf51db7b4535ff79
Referenced In Project/Scope: Grouper UI:compile
flexmark-ext-wikilink-0.64.8.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

flexmark-html2md-converter-0.64.8.jar

Description:

flexmark-java customizable extension to convert HTML to Markdown

File Path: /home/grprdist/.m2/repository/com/vladsch/flexmark/flexmark-html2md-converter/0.64.8/flexmark-html2md-converter-0.64.8.jar
MD5: c94840ab7bc1c309e22e4d9349d7fbe0
SHA1: a4b9dc984710931e98fdf62479784f789c0f5e6d
SHA256:3f24a90a8fedd6708f06be72bbc9f5f5211abc49c35ee95918ce7b0b41651e62
Referenced In Project/Scope: Grouper UI:compile
flexmark-html2md-converter-0.64.8.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

flexmark-jira-converter-0.64.8.jar

Description:

flexmark-java extension for jira_converter

File Path: /home/grprdist/.m2/repository/com/vladsch/flexmark/flexmark-jira-converter/0.64.8/flexmark-jira-converter-0.64.8.jar
MD5: 65d6ffdd133ea053da9465dabfdb7633
SHA1: 6a1997f1b8c2ef8426c0330d9be41f3f32edb82c
SHA256:ccc1c3a9659a104b75a53a2321e9c1d4cedb05acd867d4366d8b8e1647bd37dd
Referenced In Project/Scope: Grouper UI:compile
flexmark-jira-converter-0.64.8.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

flexmark-util-0.64.8.jar

Description:

flexmark-java utility classes

File Path: /home/grprdist/.m2/repository/com/vladsch/flexmark/flexmark-util/0.64.8/flexmark-util-0.64.8.jar
MD5: f54b38687f0b77f9955056ed3fcccc0b
SHA1: e7aad89229a58c9ac56e09c04a8f9b012d137bff
SHA256:1e24c891dac9532bb722be7122c7026fb47868c3de36c02400eed8e9ad535727
Referenced In Project/Scope: Grouper UI:compile
flexmark-util-0.64.8.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

flexmark-util-ast-0.64.8.jar

Description:

flexmark-java ast utility classes

File Path: /home/grprdist/.m2/repository/com/vladsch/flexmark/flexmark-util-ast/0.64.8/flexmark-util-ast-0.64.8.jar
MD5: b922dbbafa059c8867874498994f3e31
SHA1: 9904d6c8e7c9e2ec63b77e9313e518918758dd84
SHA256:a5342f644c6a5f37d502f225c3a0cb699c263621c82e720d9c08eba5a9f3b8d3
Referenced In Project/Scope: Grouper UI:compile
flexmark-util-ast-0.64.8.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

flexmark-util-builder-0.64.8.jar

Description:

flexmark-java builder utility classes

File Path: /home/grprdist/.m2/repository/com/vladsch/flexmark/flexmark-util-builder/0.64.8/flexmark-util-builder-0.64.8.jar
MD5: c4f513ffe6053d4b564bc9b827902db4
SHA1: 79f4593ce00d99b786425cabb12cc13bf785374b
SHA256:afb9c88d9f652451e75f1ab069ad7ddd791d712eb211c51d8d2a83494240875d
Referenced In Project/Scope: Grouper UI:compile
flexmark-util-builder-0.64.8.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

flexmark-util-collection-0.64.8.jar

Description:

flexmark-java collection utility classes

File Path: /home/grprdist/.m2/repository/com/vladsch/flexmark/flexmark-util-collection/0.64.8/flexmark-util-collection-0.64.8.jar
MD5: b08011e78ca2c0d568903f3925466166
SHA1: 40e82ad00bb159ee878557fa8312ed7d95f4b297
SHA256:031ff01408d0f54c6235db18d451dc6e6b15b859b0ec1e40ff3429a82375082a
Referenced In Project/Scope: Grouper UI:compile
flexmark-util-collection-0.64.8.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

flexmark-util-data-0.64.8.jar

Description:

flexmark-java data utility classes

File Path: /home/grprdist/.m2/repository/com/vladsch/flexmark/flexmark-util-data/0.64.8/flexmark-util-data-0.64.8.jar
MD5: 91e1d2623fe6a51a4779dfb56d4c17da
SHA1: a3f92abd0acbb4d1f12dfd3d6128f73d245d6ba9
SHA256:83ceb5989ab0205054bf1b42446f55cb6da14c10aa7c2bda05d6a2504670f353
Referenced In Project/Scope: Grouper UI:compile
flexmark-util-data-0.64.8.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

flexmark-util-dependency-0.64.8.jar

Description:

flexmark-java dependency utility classes

File Path: /home/grprdist/.m2/repository/com/vladsch/flexmark/flexmark-util-dependency/0.64.8/flexmark-util-dependency-0.64.8.jar
MD5: e1a664a8cb4c9dcd41d1fed79521eeb6
SHA1: 392bc415728aee6fdb9aded0004b0bf6c15e80ac
SHA256:e41adb5e8144699b61b78d50eb004eeb7de84f90c4c63626609e6cee5ea28b42
Referenced In Project/Scope: Grouper UI:compile
flexmark-util-dependency-0.64.8.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

flexmark-util-format-0.64.8.jar

Description:

flexmark-java format utility classes

File Path: /home/grprdist/.m2/repository/com/vladsch/flexmark/flexmark-util-format/0.64.8/flexmark-util-format-0.64.8.jar
MD5: f1870467badaf33a3a1fe81119e7967b
SHA1: 12bb34f8d1d3d3678b540cb75726414eb910e327
SHA256:6c9ac87686474edf0117b3f838d9dcb3b965fa72be4998d2177b598013679f73
Referenced In Project/Scope: Grouper UI:compile
flexmark-util-format-0.64.8.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

flexmark-util-html-0.64.8.jar

Description:

flexmark-java html utility classes

File Path: /home/grprdist/.m2/repository/com/vladsch/flexmark/flexmark-util-html/0.64.8/flexmark-util-html-0.64.8.jar
MD5: db48d2098c60bdd92f42a65d03b1819a
SHA1: 1ed09f6b6a57be2797aee9c9dfcbeab06afa120b
SHA256:5b19e6506aff7913c74ad725af7c2b8a9f23958e6324bf0710c5a645a4663017
Referenced In Project/Scope: Grouper UI:compile
flexmark-util-html-0.64.8.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

flexmark-util-misc-0.64.8.jar

Description:

flexmark-java misc utility classes

File Path: /home/grprdist/.m2/repository/com/vladsch/flexmark/flexmark-util-misc/0.64.8/flexmark-util-misc-0.64.8.jar
MD5: 098b129e71db2bd128c045f6651b31b3
SHA1: 6d0b133faee38c41368ee3c67f0df4498ffe3c25
SHA256:74472ca81a9080e51ea1a4f11c270898e3d6c242c92275fab47eb993806c8f2b
Referenced In Project/Scope: Grouper UI:compile
flexmark-util-misc-0.64.8.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

flexmark-util-options-0.64.8.jar

Description:

flexmark-java options utility classes

File Path: /home/grprdist/.m2/repository/com/vladsch/flexmark/flexmark-util-options/0.64.8/flexmark-util-options-0.64.8.jar
MD5: aeff736d365118e93a039ed22745b95f
SHA1: 4b17bc1639c2a874d93a5bb89f78bf0765e3e4c7
SHA256:2489f41e9caf1d9f8061833b311b25403925cbb631fff2b8c069192804d6fc88
Referenced In Project/Scope: Grouper UI:compile
flexmark-util-options-0.64.8.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

flexmark-util-sequence-0.64.8.jar

Description:

flexmark-java sequence utility classes

File Path: /home/grprdist/.m2/repository/com/vladsch/flexmark/flexmark-util-sequence/0.64.8/flexmark-util-sequence-0.64.8.jar
MD5: c52d3432485fb05dadf040323ac3e279
SHA1: 985913246df64fe7e768eb0664b45dedea7536cf
SHA256:6e22976fe4e9b8de94fd529991ecb2d79cc482aad94985367470a93be1d82631
Referenced In Project/Scope: Grouper UI:compile
flexmark-util-sequence-0.64.8.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

flexmark-util-visitor-0.64.8.jar

Description:

flexmark-java visitor utility classes

File Path: /home/grprdist/.m2/repository/com/vladsch/flexmark/flexmark-util-visitor/0.64.8/flexmark-util-visitor-0.64.8.jar
MD5: 969d8f948f9d3cc8f5b1f96665c9f207
SHA1: a8178ba6dfd7a958353a60b3a51fe7edb1578b49
SHA256:d9b3002a833a078c45e139568b306dab0ac117ff9046c6a1f9e180c0154563fc
Referenced In Project/Scope: Grouper UI:compile
flexmark-util-visitor-0.64.8.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

geronimo-jms_2.0_spec-1.0-alpha-2.jar

Description:

Java Message Service 2.0 API

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/org/apache/geronimo/specs/geronimo-jms_2.0_spec/1.0-alpha-2/geronimo-jms_2.0_spec-1.0-alpha-2.jar
MD5: bd94cfcc9f711642d280681330b14844
SHA1: 8d8a4d5a80138ba4ebc7b5509989e3d7013c7e74
SHA256:62a109edef3de718b0cb600bf040b4be5e32c683a57ee16f9f8a89537bf5da51
Referenced In Project/Scope: Grouper UI:compile
geronimo-jms_2.0_spec-1.0-alpha-2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

groovy-2.5.23.jar

Description:

Groovy: A powerful, dynamic language for the JVM

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/org/codehaus/groovy/groovy/2.5.23/groovy-2.5.23.jar
MD5: c20fa41709c06bb5b51a8817cdf57c25
SHA1: 746d55b0ffd158f7ba0f9b999850a44a6628b498
SHA256:fe3238310d2334b37ed8e6ed219f8a33429eae6548085e822e4d1aad3a471579
Referenced In Project/Scope: Grouper UI:compile
groovy-2.5.23.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

groovy-xml-2.5.23.jar

Description:

Groovy: A powerful, dynamic language for the JVM

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/org/codehaus/groovy/groovy-xml/2.5.23/groovy-xml-2.5.23.jar
MD5: f5bea4b2abc70acbcf535c2adb63fe36
SHA1: 54b35dd3feffec48837f1c267b2a2ada47568d7f
SHA256:96c36044d69b1ce7a4617992f26a8771688a66431fa8532da19e826b0ce16163
Referenced In Project/Scope: Grouper UI:compile
groovy-xml-2.5.23.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

gson-2.13.2.jar

Description:

Gson JSON library

License:

Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/com/google/code/gson/gson/2.13.2/gson-2.13.2.jar
MD5: a2c47e14ce5e956105458fe455f5d542
SHA1: 48b8230771e573b54ce6e867a9001e75977fe78e
SHA256:dd0ce1b55a3ed2080cb70f9c655850cda86c206862310009dcb5e5c95265a5e0
Referenced In Project/Scope: Grouper UI:compile
gson-2.13.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

hibernate-c3p0-5.6.15.Final.jar

Description:

Integration for c3p0 Connection pooling into Hibernate ORM

License:

GNU Library General Public License v2.1 or later: https://www.opensource.org/licenses/LGPL-2.1
File Path: /home/grprdist/.m2/repository/org/hibernate/hibernate-c3p0/5.6.15.Final/hibernate-c3p0-5.6.15.Final.jar
MD5: bb08e7c3a5bc01ca97f85879fa269227
SHA1: 60b7e730f1f4ff3cfe1f9c8abc4f1b5d2dd3d512
SHA256:02714f37cc3a35d7a2197de91db631a2c4dfd3f705ab2f66c5aab7401e0d4cc3
Referenced In Project/Scope: Grouper UI:compile
hibernate-c3p0-5.6.15.Final.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

hibernate-commons-annotations-5.1.2.Final.jar

Description:

Common reflection code used in support of annotation processing

License:

GNU Library General Public License v2.1 or later: http://www.opensource.org/licenses/LGPL-2.1
File Path: /home/grprdist/.m2/repository/org/hibernate/common/hibernate-commons-annotations/5.1.2.Final/hibernate-commons-annotations-5.1.2.Final.jar
MD5: 2a2490b3eb8e7585a6a899d27d7ed43f
SHA1: e59ffdbc6ad09eeb33507b39ffcf287679a498c8
SHA256:1c7ce712b2679fea0a5441eb02a04144297125b768944819be0765befb996275
Referenced In Project/Scope: Grouper UI:compile
hibernate-commons-annotations-5.1.2.Final.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

hibernate-core-5.6.15.Final.jar

Description:

Hibernate's core ORM functionality

License:

GNU Library General Public License v2.1 or later: https://www.opensource.org/licenses/LGPL-2.1
File Path: /home/grprdist/.m2/repository/org/hibernate/hibernate-core/5.6.15.Final/hibernate-core-5.6.15.Final.jar
MD5: 0bc0673435fbabce62a7a0d5fe967fd8
SHA1: ab14b7cef1fdff654ca81923048a6034d6c7cfa7
SHA256:9b5a7e1faf094d98c9e33b6a27c4cae42e52f65b139091c08b9a0b4a9858b207
Referenced In Project/Scope: Grouper UI:compile
hibernate-core-5.6.15.Final.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

CVE-2026-0603 (OSSINDEX)  

A flaw was found in Hibernate. A remote attacker with low privileges could exploit a second-order SQL injection vulnerability by providing specially crafted, unsanitized non-alphanumeric characters in the ID column when the InlineIdsOrClauseBuilder is used. This could lead to sensitive information disclosure, such as reading system files, and allow for data manipulation or deletion within the application's database, resulting in an application level denial of service.
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CVSSv3:
  • Base Score: HIGH (8.300000190734863)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

References:

Vulnerable Software & Versions (OSSINDEX):

  • cpe:2.3:a:org.hibernate:hibernate-core:5.6.15.Final:*:*:*:*:*:*:*

httpclient-4.5.14.jar

Description:

   Apache HttpComponents Client
  

File Path: /home/grprdist/.m2/repository/org/apache/httpcomponents/httpclient/4.5.14/httpclient-4.5.14.jar
MD5: 2cb357c4b763f47e58af6cad47df6ba3
SHA1: 1194890e6f56ec29177673f2f12d0b8e627dec98
SHA256:c8bc7e1c51a6d4ce72f40d2ebbabf1c4b68bfe76e732104b04381b493478e9d6
Referenced In Project/Scope: Grouper UI:compile
httpclient-4.5.14.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

httpcore-4.4.16.jar

Description:

   Apache HttpComponents Core (blocking I/O)
  

File Path: /home/grprdist/.m2/repository/org/apache/httpcomponents/httpcore/4.4.16/httpcore-4.4.16.jar
MD5: 28d2cd9bf8789fd2ec774fb88436ebd1
SHA1: 51cf043c87253c9f58b539c9f7e44c8894223850
SHA256:6c9b3dd142a09dc468e23ad39aad6f75a0f2b85125104469f026e52a474e464f
Referenced In Project/Scope: Grouper UI:compile
httpcore-4.4.16.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

httpmime-4.5.14.jar

Description:

   Apache HttpComponents HttpClient - MIME coded entities
  

File Path: /home/grprdist/.m2/repository/org/apache/httpcomponents/httpmime/4.5.14/httpmime-4.5.14.jar
MD5: 714c4ae31c40e6633c0bcaa4e6264153
SHA1: 6662758a1f1cb1149cf916bdac28332e0902ec44
SHA256:d401243d5c6eae928a37121b6e819158c8c32ea0584793e7285bb489ab2a3d17
Referenced In Project/Scope: Grouper UI:compile
httpmime-4.5.14.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

istack-commons-runtime-3.0.7.jar

Description:

istack common utility code

License:

https://glassfish.java.net/public/CDDL+GPL_1_1.html, https://glassfish.java.net/public/CDDL+GPL_1_1.html
File Path: /home/grprdist/.m2/repository/com/sun/istack/istack-commons-runtime/3.0.7/istack-commons-runtime-3.0.7.jar
MD5: 83e9617b86023b91bd54f65c09838f4b
SHA1: c197c86ceec7318b1284bffb49b54226ca774003
SHA256:6443e10ba2e259fb821d9b6becf10db5316285fc30c53cec9d7b19a3877e7fdf
Referenced In Project/Scope: Grouper UI:compile
istack-commons-runtime-3.0.7.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

jackson-annotations-2.22.jar

Description:

Core annotations used for value types, used by Jackson data binding package.
  

License:

The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/com/fasterxml/jackson/core/jackson-annotations/2.22/jackson-annotations-2.22.jar
MD5: 04c11c456fd1e21b9a21c25c665109cc
SHA1: 15c67f9498d6934cff9510fc70c5a12e52290457
SHA256:21ddb598807d3a51a876704eb979d9296e1c6a6f47ab1826ff88c6d6a127a2d0
Referenced In Project/Scope: Grouper UI:compile
jackson-annotations-2.22.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

jackson-core-2.22.1.jar

Description:

Core Jackson processing abstractions (aka Streaming API), implementation for JSON

License:

The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/com/fasterxml/jackson/core/jackson-core/2.22.1/jackson-core-2.22.1.jar
MD5: 09e866bcd73613665ef49f5086704fb1
SHA1: da7ffb60088d7e8f37ecdd3b617520971cc7b9bf
SHA256:941ff029bcdb93e83d209ce516c1a7fb8bbac07d0a2fa122f5bf194b2cd7b4f4
Referenced In Project/Scope: Grouper UI:compile
jackson-core-2.22.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

jackson-databind-2.22.1.jar

Description:

General data-binding functionality for Jackson: works on core streaming API

License:

The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.22.1/jackson-databind-2.22.1.jar
MD5: df2dcf8d581836d48aae7387311cba93
SHA1: 9e2fb91831cce9cb9262909cd76647508949f232
SHA256:7dcd7e53bec1f56c7ad278bd1ca0840bebcc595d61ce44d6a8439abb75b965b2
Referenced In Project/Scope: Grouper UI:compile
jackson-databind-2.22.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

jackson-dataformat-cbor-2.17.2.jar

Description:

Support for reading and writing Concise Binary Object Representation
([CBOR](https://www.rfc-editor.org/info/rfc7049)
encoded data using Jackson abstractions (streaming API, data binding, tree model)
  

License:

The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/com/fasterxml/jackson/dataformat/jackson-dataformat-cbor/2.17.2/jackson-dataformat-cbor-2.17.2.jar
MD5: 8791b95fb115255e534697a8f15f23b4
SHA1: 57fa7c1b5104bbc4599278d13933a937ee058e68
SHA256:1d7dc634ba3d7981d7017f4f44d43cf371e922c80028b4eb3e5374ce6546d5f6
Referenced In Project/Scope: Grouper UI:compile
jackson-dataformat-cbor-2.17.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

jakarta.activation-api-2.1.4.jar

Description:

  Specification

License:

EDL 1.0: http://www.eclipse.org/org/documents/edl-v10.php
File Path: /home/grprdist/.m2/repository/jakarta/activation/jakarta.activation-api/2.1.4/jakarta.activation-api-2.1.4.jar
MD5: bc1602eee7bc61a0b86f14bbbb0cc794
SHA1: 9e5c2a0d75dde71a0bedc4dbdbe47b78a5dc50f8
SHA256:c9db52100ce6c8aac95cc39075f95720d2e561b11f8051b81c121ad4effd7004
Referenced In Project/Scope: Grouper UI:compile
jakarta.activation-api-2.1.4.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

jakarta.mail-api-2.1.5.jar

Description:

  Specification API

License:

EPL 2.0: http://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html
EDL 1.0: http://www.eclipse.org/org/documents/edl-v10.php
File Path: /home/grprdist/.m2/repository/jakarta/mail/jakarta.mail-api/2.1.5/jakarta.mail-api-2.1.5.jar
MD5: a1872951f46b87594806bb01e342a468
SHA1: be9b3b677ed6083f575c437ebc442a6a4bd2b931
SHA256:aa493753acb7a8c45ba8f4c9cf1230a74e20237056dd5b5c8bc86c583e8cfa0e
Referenced In Project/Scope: Grouper UI:compile
jakarta.mail-api-2.1.5.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

jakarta.xml.bind-api-4.0.4.jar

Description:

Jakarta XML Binding API 4.0 Design Specification

License:

http://www.eclipse.org/org/documents/edl-v10.php
File Path: /home/grprdist/.m2/repository/jakarta/xml/bind/jakarta.xml.bind-api/4.0.4/jakarta.xml.bind-api-4.0.4.jar
MD5: 6dd465a232e545193ab8ab77cc4fbdb9
SHA1: d6d2327f3817d9a33a3b6b8f2e15a96bc2e7afdc
SHA256:c507ca69a8c6dd11bf4afeec9e0d412c4fa3933fffb0a84680ea5727e8472124
Referenced In Project/Scope: Grouper UI:runtime
jakarta.xml.bind-api-4.0.4.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.quartz-scheduler/quartz@2.5.2

Identifiers

jandex-2.4.2.Final.jar

Description:

Parent POM for JBoss projects. Provides default project build configuration.

License:

Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/org/jboss/jandex/2.4.2.Final/jandex-2.4.2.Final.jar
MD5: 489f7a97d2ed7ae34ea56d01b3566d57
SHA1: 1e1c385990b258ff1a24c801e84aebbacf70eb39
SHA256:3f2ce55c7d71e744581488dc5105806aa8084c08e6e916a019bab8f8698994f0
Referenced In Project/Scope: Grouper UI:compile
jandex-2.4.2.Final.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

java-ipv6-0.17.jar

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/com/googlecode/java-ipv6/java-ipv6/0.17/java-ipv6-0.17.jar
MD5: 7eab662f5ec5c0f1d964e1c551a5ac02
SHA1: 243426a162fa169ad40f5f59cb957321f00cba3f
SHA256:37cf71baf707041cb494834c559ad12b631f5c7747c804ec19598bc0e0f01162
Referenced In Project/Scope: Grouper UI:compile
java-ipv6-0.17.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

java-jwt-3.19.4.jar

Description:

Java implementation of JSON Web Token (JWT)

License:

The MIT License (MIT): https://raw.githubusercontent.com/auth0/java-jwt/master/LICENSE
File Path: /home/grprdist/.m2/repository/com/auth0/java-jwt/3.19.4/java-jwt-3.19.4.jar
MD5: f77b856f3d369a0017928d113646daa4
SHA1: 0e1f57df0730b10d2b258a5e3b4058389a54459b
SHA256:0a3a682308d27aa710441860915d40e7c641720b5bed036bb3eaf9683458288e
Referenced In Project/Scope: Grouper UI:compile
java-jwt-3.19.4.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

javassist-3.30.2-GA.jar

Description:

    Javassist (JAVA programming ASSISTant) makes Java bytecode manipulation
    simple. It is a class library for editing bytecodes in Java.
  

License:

MPL 1.1: https://www.mozilla.org/en-US/MPL/1.1/
LGPL 2.1: https://www.gnu.org/licenses/lgpl-2.1.html
Apache License 2.0: https://www.apache.org/licenses/LICENSE-2.0
File Path: /home/grprdist/.m2/repository/org/javassist/javassist/3.30.2-GA/javassist-3.30.2-GA.jar
MD5: f5b827b8ddec0629cc7a6d7dafc45999
SHA1: 284580b5e42dfa1b8267058566435d9e93fae7f7
SHA256:eba37290994b5e4868f3af98ff113f6244a6b099385d9ad46881307d3cb01aaf
Referenced In Project/Scope: Grouper UI:compile
javassist-3.30.2-GA.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

javax.activation-api-1.2.0.jar

Description:

JavaBeans Activation Framework API jar

License:

https://github.com/javaee/activation/blob/master/LICENSE.txt
File Path: /home/grprdist/.m2/repository/javax/activation/javax.activation-api/1.2.0/javax.activation-api-1.2.0.jar
MD5: 5e50e56bcf4a3ef3bc758f69f7643c3b
SHA1: 85262acf3ca9816f9537ca47d5adeabaead7cb16
SHA256:43fdef0b5b6ceb31b0424b208b930c74ab58fac2ceeb7b3f6fd3aeb8b5ca4393
Referenced In Project/Scope: Grouper UI:compile
javax.activation-api-1.2.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

javax.persistence-api-2.2.jar

Description:

Java(TM) Persistence API

License:

Eclipse Public License v1.0: http://www.eclipse.org/legal/epl-v10.html
Eclipse Distribution License v. 1.0: http://www.eclipse.org/org/documents/edl-v10.php
File Path: /home/grprdist/.m2/repository/javax/persistence/javax.persistence-api/2.2/javax.persistence-api-2.2.jar
MD5: e6520b3435f5b6d58eee415b5542abf8
SHA1: 25665ac8c0b62f50e6488173233239120fc52c96
SHA256:5578b71b37999a5eaed3fea0d14aa61c60c6ec6328256f2b63472f336318baf4
Referenced In Project/Scope: Grouper UI:compile
javax.persistence-api-2.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

javax.servlet-api-3.1.0.jar

Description:

Java(TM) Servlet 3.1 API Design Specification

License:

CDDL + GPLv2 with classpath exception: https://glassfish.dev.java.net/nonav/public/CDDL+GPL.html
File Path: /home/grprdist/.m2/repository/javax/servlet/javax.servlet-api/3.1.0/javax.servlet-api-3.1.0.jar
MD5: 79de69e9f5ed8c7fcb8342585732bbf7
SHA1: 3cd63d075497751784b2fa84be59432f4905bf7c
SHA256:af456b2dd41c4e82cf54f3e743bc678973d9fe35bd4d3071fa05c7e5333b8482
Referenced In Project/Scope: Grouper UI:provided
javax.servlet-api-3.1.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper-ui@7.0.0-SNAPSHOT

Identifiers

javax.servlet.jsp-api-2.3.3.jar

Description:

Java.net - The Source for Java Technology Collaboration

License:

CDDL + GPLv2 with classpath exception: ://oss.oracle.com/licenses/CDDL+GPL-1.1
File Path: /home/grprdist/.m2/repository/javax/servlet/jsp/javax.servlet.jsp-api/2.3.3/javax.servlet.jsp-api-2.3.3.jar
MD5: f6676a5961328c41c5e722da5e48d047
SHA1: 81191ab80e342912dc9cea735c30ff4eddc64de3
SHA256:409a534d275ef0958a2c1692472da30e3706bfe6933d56c039376f53f13689b7
Referenced In Project/Scope: Grouper UI:provided
javax.servlet.jsp-api-2.3.3.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper-ui@7.0.0-SNAPSHOT

Identifiers

javax.servlet.jsp.jstl-api-1.2.2.jar

Description:

Java.net - The Source for Java Technology Collaboration

License:

CDDL + GPLv2 with classpath exception: http://glassfish.dev.java.net/nonav/public/CDDL+GPL.html
File Path: /home/grprdist/.m2/repository/javax/servlet/jsp/jstl/javax.servlet.jsp.jstl-api/1.2.2/javax.servlet.jsp.jstl-api-1.2.2.jar
MD5: f584b3367815d97e247f64daa368571f
SHA1: 8c180218e860de0347bd2908328e2c67cec46442
SHA256:5524b3542fe832b76386e72f60f737b83ba064ff12aa5cd0cd42afa191af4d90
Referenced In Project/Scope: Grouper UI:compile
javax.servlet.jsp.jstl-api-1.2.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper-ui@7.0.0-SNAPSHOT

Identifiers

jaxb-api-2.3.1.jar

Description:

JAXB (JSR 222) API

License:

https://oss.oracle.com/licenses/CDDL+GPL-1.1, https://oss.oracle.com/licenses/CDDL+GPL-1.1
File Path: /home/grprdist/.m2/repository/javax/xml/bind/jaxb-api/2.3.1/jaxb-api-2.3.1.jar
MD5: bcf270d320f645ad19f5edb60091e87f
SHA1: 8531ad5ac454cc2deb9d4d32c40c4d7451939b5d
SHA256:88b955a0df57880a26a74708bc34f74dcaf8ebf4e78843a28b50eae945732b06
Referenced In Project/Scope: Grouper UI:compile
jaxb-api-2.3.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

jaxb-runtime-2.3.1.jar

Description:

JAXB (JSR 222) Reference Implementation

File Path: /home/grprdist/.m2/repository/org/glassfish/jaxb/jaxb-runtime/2.3.1/jaxb-runtime-2.3.1.jar
MD5: 848098e3eda0d37738d51a7acacd8e95
SHA1: dd6dda9da676a54c5b36ca2806ff95ee017d8738
SHA256:45fecfa5c8217ce1f3652ab95179790ec8cc0dec0384bca51cbeb94a293d9f2f
Referenced In Project/Scope: Grouper UI:compile
jaxb-runtime-2.3.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

jboss-logging-3.6.1.Final.jar

Description:

The JBoss Logging Framework

License:

Apache License 2.0: https://repository.jboss.org/licenses/apache-2.0.txt
File Path: /home/grprdist/.m2/repository/org/jboss/logging/jboss-logging/3.6.1.Final/jboss-logging-3.6.1.Final.jar
MD5: acab989faf62db02c092448e95614fab
SHA1: 886afbb445b4016a37c8960a7aef6ebd769ce7e5
SHA256:5e08a4b092dc85b337f0910a740571d8720cfa565fabd880a8caf94a657ca416
Referenced In Project/Scope: Grouper UI:compile
jboss-logging-3.6.1.Final.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

jboss-transaction-api_1.2_spec-1.1.1.Final.jar

Description:

The Java Transaction 1.2 API classes

License:

Common Development and Distribution License: http://repository.jboss.org/licenses/cddl.txt
GNU General Public License, Version 2 with the Classpath Exception: http://repository.jboss.org/licenses/gpl-2.0-ce.txt
File Path: /home/grprdist/.m2/repository/org/jboss/spec/javax/transaction/jboss-transaction-api_1.2_spec/1.1.1.Final/jboss-transaction-api_1.2_spec-1.1.1.Final.jar
MD5: 1e633c47138aba999d39692a31a1a124
SHA1: a8485cab9484dda36e9a8c319e76b5cc18797b58
SHA256:a310a50b9bdc44aaf36362dc9bb212235a147ffa8ef72dc9544a39c329eabbc3
Referenced In Project/Scope: Grouper UI:compile
jboss-transaction-api_1.2_spec-1.1.1.Final.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

jcip-annotations-1.0-1.jar

Description:

    A clean room implementation of the JCIP Annotations based entirely on the specification provided by the javadocs.
  

License:

Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/com/github/stephenc/jcip/jcip-annotations/1.0-1/jcip-annotations-1.0-1.jar
MD5: d62dbfa8789378457ada685e2f614846
SHA1: ef31541dd28ae2cefdd17c7ebf352d93e9058c63
SHA256:4fccff8382aafc589962c4edb262f6aa595e34f1e11e61057d1c6a96e8fc7323
Referenced In Project/Scope: Grouper UI:compile
jcip-annotations-1.0-1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

jetty-6.1.26.jar

Description:

Jetty server core

License:

http://www.apache.org/licenses/LICENSE-2.0, http://www.eclipse.org/org/documents/epl-v10.php
File Path: /home/grprdist/.m2/repository/org/mortbay/jetty/jetty/6.1.26/jetty-6.1.26.jar
MD5: 12b65438bbaf225102d0396c21236052
SHA1: 2f546e289fddd5b1fab1d4199fbb6e9ef43ee4b0
SHA256:21091d3a9c1349f640fdc421504a604c040ed89087ecc12afbe32353326ed4e5
Referenced In Project/Scope: Grouper UI:compile
jetty-6.1.26.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

CVE-2011-4461  

Jetty 8.1.0.RC2 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.
CWE-310 Cryptographic Issues

CVSSv3:
  • Base Score: MEDIUM (5.3)
  • Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:3.9/RC:R/MAV:A
CVSSv2:
  • Base Score: MEDIUM (5.0)
  • Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P

References:

Vulnerable Software & Versions: (show all)

CVE-2009-1523  

Directory traversal vulnerability in the HTTP server in Mort Bay Jetty 5.1.14, 6.x before 6.1.17, and 7.x through 7.0.0.M2 allows remote attackers to access arbitrary files via directory traversal sequences in the URI.
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSSv2:
  • Base Score: MEDIUM (5.0)
  • Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N

References:

Vulnerable Software & Versions: (show all)

jline-2.14.6.jar

License:

The BSD License: http://www.opensource.org/licenses/bsd-license.php
File Path: /home/grprdist/.m2/repository/jline/jline/2.14.6/jline-2.14.6.jar
MD5: 480423551649bc6980b43f09e4717272
SHA1: c3aeac59c022bdc497c8c48ed86fa50450e4896a
SHA256:97d1acaac82409be42e622d7a54d3ae9d08517e8aefdea3d2ba9791150c2f02d
Referenced In Project/Scope: Grouper UI:compile
jline-2.14.6.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

CVE-2023-50572  

An issue in the component GroovyEngine.execute of jline-groovy v3.24.1 allows attackers to cause an OOM (OutofMemory) error.
CWE-787 Out-of-bounds Write

CVSSv3:
  • Base Score: MEDIUM (5.5)
  • Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:1.8/RC:R/MAV:A

References:

Vulnerable Software & Versions:

jmespath-java-1.12.796.jar

Description:

Implementation of the JMES Path JSON Query langauge for Java.

License:

Apache License, Version 2.0: https://aws.amazon.com/apache2.0
File Path: /home/grprdist/.m2/repository/com/amazonaws/jmespath-java/1.12.796/jmespath-java-1.12.796.jar
MD5: f919a47aaee67a023d7b46e8dbeb87d7
SHA1: 15b0546764e69988ef7adb698995c2315c054885
SHA256:d111e0af7ddd73e2bada51652d6708b2006abef8a248f1d384c8094c7a71a11a
Referenced In Project/Scope: Grouper UI:compile
jmespath-java-1.12.796.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

joda-time-2.14.0.jar

Description:

Date and time library to replace JDK date handling

License:

Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/joda-time/joda-time/2.14.0/joda-time-2.14.0.jar
MD5: ce5d368699f16abb55616b6b9fcb34dd
SHA1: 1fa665c1ce64a2c8c94f63fc5c1ee7bd742d2022
SHA256:1e2da6f9eb65f20a25d9a3186831ed2b3fb14f7a48e1ef8206135ee58cb143d3
Referenced In Project/Scope: Grouper UI:compile
joda-time-2.14.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

jsch-0.2.25.jar

Description:

JSch is a pure Java implementation of SSH2

License:

Revised BSD: https://github.com/mwiede/jsch/blob/master/LICENSE.txt
Revised BSD: https://github.com/mwiede/jsch/blob/master/LICENSE.JZlib.txt
ISC: https://github.com/mwiede/jsch/blob/master/LICENSE.jBCrypt.txt
File Path: /home/grprdist/.m2/repository/com/github/mwiede/jsch/0.2.25/jsch-0.2.25.jar
MD5: 81639ce6aed4f7abac2cf5030e77a1a5
SHA1: fe6d1440dc0e852a7aa71b191b42e4541b80d0b2
SHA256:069a4e86fe1e5dbfe7bb504a6e4f973659898933e560e6649ae40da8c7070d1c
Referenced In Project/Scope: Grouper UI:compile
jsch-0.2.25.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

json-smart-2.5.2.jar

Description:

JSON (JavaScript Object Notation) is a lightweight data-interchange format. It is easy for humans to read and write. It is easy for machines to parse and generate. It is based on a subset of the JavaScript Programming Language, Standard ECMA-262 3rd Edition - December 1999. JSON is a text format that is completely language independent but uses conventions that are familiar to programmers of the C-family of languages, including C, C++, C#, Java, JavaScript, Perl, Python, and many others. These properties make JSON an ideal data-interchange language.

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/net/minidev/json-smart/2.5.2/json-smart-2.5.2.jar
MD5: e3ad34c55c0d2627255f79f4411c6bdd
SHA1: 95d166b18f95907be0f46cdb9e1c0695eed03387
SHA256:4fbdedb0105cedc7f766b95c297d2e88fb6a560da48f3bbaa0cc538ea8b7bf71
Referenced In Project/Scope: Grouper UI:compile
json-smart-2.5.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

jsoup-1.21.1.jar

Description:

jsoup is a Java library that simplifies working with real-world HTML and XML. It offers an easy-to-use API for URL fetching, data parsing, extraction, and manipulation using DOM API methods, CSS, and xpath selectors. jsoup implements the WHATWG HTML5 specification, and parses HTML to the same DOM as modern browsers.

License:

The MIT License: https://jsoup.org/license
File Path: /home/grprdist/.m2/repository/org/jsoup/jsoup/1.21.1/jsoup-1.21.1.jar
MD5: 943973ee41e68a68371f2244d14e158d
SHA1: c5dad601fd4c927a5c09ca76e8c1f32de73be97a
SHA256:436adf71fe9f326e04fe134cd2785b261f0f4b9b60876adda1de3b6919463394
Referenced In Project/Scope: Grouper UI:compile
jsoup-1.21.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

jta-1.1.jar

Description:

    The javax.transaction package. It is appropriate for inclusion in a classpath, and may be added to a Java 2 installation.
  

File Path: /home/grprdist/.m2/repository/javax/transaction/jta/1.1/jta-1.1.jar
MD5: 82a10ce714f411b28f13850059de09ee
SHA1: 2ca09f0b36ca7d71b762e14ea2ff09d5eac57558
SHA256:b8ec163b4a47bad16f9a0b7d03c3210c6b0a29216d768031073ac20817c0ba50
Referenced In Project/Scope: Grouper UI:compile
jta-1.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

lang-tag-1.7.jar

Description:

Java implementation of "Tags for Identifying Languages" (RFC 5646)

License:

The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/com/nimbusds/lang-tag/1.7/lang-tag-1.7.jar
MD5: 31b8a4f76fdbf21f1d667f9d6618e0b2
SHA1: 97c73ecd70bc7e8eefb26c5eea84f251a63f1031
SHA256:e8c1c594e2425bdbea2d860de55c69b69fc5d59454452449a0f0913c2a5b8a31
Referenced In Project/Scope: Grouper UI:compile
lang-tag-1.7.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

ldaptive-2.4.2.jar

Description:

Ldaptive API

License:

https://www.apache.org/licenses/LICENSE-2.0.txt, https://www.gnu.org/licenses/lgpl-3.0.txt
File Path: /home/grprdist/.m2/repository/org/ldaptive/ldaptive/2.4.2/ldaptive-2.4.2.jar
MD5: 08f6b2b99d4fb6d0c87c4c7b05720eeb
SHA1: f8283f1c25d3d519a9dbb585aaeea510e1f5f898
SHA256:b755a9c159ea33d5e476fb30c0c5c049ad8a4e2d4c3ec03ffecbe830146941e9
Referenced In Project/Scope: Grouper UI:compile
ldaptive-2.4.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

log4j-core-2.26.0.jar

Description:

A versatile, industrial-grade, and reference implementation of the Log4j API.
    It bundles a rich set of components to assist various use cases:
    Appenders targeting files, network sockets, databases, SMTP servers;
    Layouts that can render CSV, HTML, JSON, Syslog, etc. formatted outputs;
    Filters that can be configured using log event rates, regular expressions, scripts, time, etc.
    It contains several extension points to introduce custom components, if needed.

License:

Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/org/apache/logging/log4j/log4j-core/2.26.0/log4j-core-2.26.0.jar
MD5: 6f35a16e514ca6d13938be57d107d139
SHA1: d267ca60b27ddb075e0b4e75e7875859717bf85f
SHA256:406bb3132c47a5d322e5c571feb0787ca84496469f346eb51f1ef2ee45499902
Referenced In Project/Scope: Grouper UI:compile
log4j-core-2.26.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper-ui@7.0.0-SNAPSHOT

Identifiers

CVE-2026-49844  

Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0.

The fix for CVE-2026-34481 did not cover all code paths: when a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 does not permit these tokens, so a conformant parser rejects the resulting document.

The defect is reachable only when both of the following conditions hold:

  *  The application uses the  message resolver https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message  of JsonTemplateLayout or any other layout that relies on MapMessage.asJson() or MapMessage.getFormattedMessage(new String[]{"JSON"}).
  *  The application logs a MapMessage that contains an attacker-controlled floating-point value.


An attacker who can supply a non-finite value can cause the affected layout to emit malformed JSON, which may corrupt the enclosing log record or disrupt downstream log ingestion and parsing.

Users are advised to upgrade to Apache Log4j API 2.25.5 or 2.26.1, both of which emit RFC 8259-compliant JSON for non-finite values.
CWE-116 Improper Encoding or Escaping of Output

CVSSv4:
  • Base Score: MEDIUM (6.3)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: MEDIUM (5.9)
  • Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N/E:2.2/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

log4j-slf4j-impl-2.26.0.jar

Description:

SLF4J 1 binding (provider) for the Log4j API.
    It forwards SLF4J 1 calls to the Log4j API.
    (Refer to the `log4j-to-slf4j` artifact for forwarding the Log4j API to SLF4J.)

License:

Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/org/apache/logging/log4j/log4j-slf4j-impl/2.26.0/log4j-slf4j-impl-2.26.0.jar
MD5: d6c3a217287eee9449bce90aa1b9668f
SHA1: eb823de5347168f764f2438a0f9f4ef86c2324a9
SHA256:6eab649c5f854ca91d857e3746b495aede27a21bb08c9f7cb172dce29612849e
Referenced In Project/Scope: Grouper UI:compile
log4j-slf4j-impl-2.26.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

lucene-analysis-common-9.12.1.jar

Description:

Apache Lucene (module: common)

License:

Apache 2: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/org/apache/lucene/lucene-analysis-common/9.12.1/lucene-analysis-common-9.12.1.jar
MD5: d8b10a65e8b18198a0c83ee0728b394f
SHA1: 86836497e35c1ab33259d9864ceb280c0016075e
SHA256:0e7534d4b6e1c3ce7af939028b3e8c1730ffb29ea5d689de2bc166c482e01b5d
Referenced In Project/Scope: Grouper UI:compile
lucene-analysis-common-9.12.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

lucene-core-9.12.1.jar

Description:

Apache Lucene (module: core)

License:

Apache 2: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/org/apache/lucene/lucene-core/9.12.1/lucene-core-9.12.1.jar
MD5: 49b3844a3650c34b74345e4c3f6896bb
SHA1: 91447c90c1180122142773b5baddaf8547124794
SHA256:8d812e9fa6dbd816808205e6cb4d7ab43a747e379c8cb31a0d6dc91050b3f97a
Referenced In Project/Scope: Grouper UI:compile
lucene-core-9.12.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

lucene-facet-9.12.1.jar

Description:

Apache Lucene (module: facet)

License:

Apache 2: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/org/apache/lucene/lucene-facet/9.12.1/lucene-facet-9.12.1.jar
MD5: c196b174dc2e47176cc3570e0c5a09c9
SHA1: 265df739cf97862931606395a10a0d0b97ff7f97
SHA256:36910f094d21907908c65eaab6f892ef1aa11081612c652b6bfafddc7b0b1ef1
Referenced In Project/Scope: Grouper UI:compile
lucene-facet-9.12.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

lucene-queries-9.12.1.jar

Description:

Apache Lucene (module: queries)

License:

Apache 2: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/org/apache/lucene/lucene-queries/9.12.1/lucene-queries-9.12.1.jar
MD5: 379f3dc54b0ec2636688b172509444c9
SHA1: 14f24315041b686683dba4bc679ca7dc6a505906
SHA256:3630f4d53203d62152cdb993a7b4f9d4e52cff2688ba549ad09cc01d5d78b5f8
Referenced In Project/Scope: Grouper UI:compile
lucene-queries-9.12.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

lucene-queryparser-9.12.1.jar

Description:

Apache Lucene (module: queryparser)

License:

Apache 2: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/org/apache/lucene/lucene-queryparser/9.12.1/lucene-queryparser-9.12.1.jar
MD5: 48624eaebd46e836d42e623fc64af235
SHA1: aa6df09a99f8881d843e9863aa1713dc9f3ed24f
SHA256:9746eb991203553ade09491ac49415e3711ec32e4ad3cd705d8d9620a32192dd
Referenced In Project/Scope: Grouper UI:compile
lucene-queryparser-9.12.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

lucene-sandbox-9.12.1.jar

Description:

Apache Lucene (module: sandbox)

License:

Apache 2: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/org/apache/lucene/lucene-sandbox/9.12.1/lucene-sandbox-9.12.1.jar
MD5: aa2e5c8fde096271e292f07c20b30c5e
SHA1: 1a66485629d60779f039fc26360f4374ef1496e7
SHA256:9aa00ce942216d513352dae89cf8588c6bdd379f82a5d8a30d8652535bd58aae
Referenced In Project/Scope: Grouper UI:compile
lucene-sandbox-9.12.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

mchange-commons-java-0.4.0.jar

Description:

mchange-commons-java

License:

GNU Lesser General Public License, Version 2.1: http://www.gnu.org/licenses/lgpl-2.1.html
Eclipse Public License, Version 1.0: http://www.eclipse.org/org/documents/epl-v10.html
File Path: /home/grprdist/.m2/repository/com/mchange/mchange-commons-java/0.4.0/mchange-commons-java-0.4.0.jar
MD5: 58852898cbb458e1efb6db6bac7d3941
SHA1: 73c3dc449de6084d49c833732147865cc1665425
SHA256:fd88e385a38df7701177b076e35048a841dc5df1118c6b2d860bba08c41bc0b6
Referenced In Project/Scope: Grouper UI:compile
mchange-commons-java-0.4.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

CVE-2026-55153 (OSSINDEX)  

mchange-commons-java is a Java library of shared utility classes used by mchange projects like the c3p0 connection pool. Prior to version 0.6.0, its JNDI ObjectFactory implementation (com.mchange.v2.naming.JavaBeanObjectFactory) will construct objects of arbitrary classes and initialize "JavaBean"-style properties, which for certain classes enables JNDI injection and "deserialization gadgets." Such initialization is unsafe for some classes: for example, setting the contentType property of a Swing JEditorPane to text/html and its text property to HTML containing a stylesheet <link> will provoke an HTTP GET on an arbitrary URL, potentially from within a trusted security domain. The problem is aggravated by the library's ReferenceIndirector, through which malicious JNDI Reference objects can be smuggled in for dereferencing wherever an application reads a Java-serialized object. This has been resolved in version 0.6.0.
CWE-470 Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

CVSSv3:
  • Base Score: HIGH (7.099999904632568)
  • Vector: CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

References:

Vulnerable Software & Versions (OSSINDEX):

  • cpe:2.3:a:com.mchange:mchange-commons-java:0.4.0:*:*:*:*:*:*:*

mxparser-1.2.2.jar

Description:

    MXParser is a fork of xpp3_min 1.1.7 containing only the parser with merged changes of the Plexus fork.
  

License:

Indiana University Extreme! Lab Software License: https://raw.githubusercontent.com/x-stream/mxparser/master/LICENSE.txt
File Path: /home/grprdist/.m2/repository/io/github/x-stream/mxparser/1.2.2/mxparser-1.2.2.jar
MD5: 9d7e42409dfdcee9bd17903015bdeae2
SHA1: 476fb3b3bb3716cad797cd054ce45f89445794e9
SHA256:aeeee23a3303d811bca8790ea7f25b534314861c03cff36dafdcc2180969eb97
Referenced In Project/Scope: Grouper UI:compile
mxparser-1.2.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

mysql-connector-j-9.5.0.jar

Description:

JDBC Type 4 driver for MySQL.

License:

The GNU General Public License, v2 with Universal FOSS Exception, v1.0
File Path: /home/grprdist/.m2/repository/com/mysql/mysql-connector-j/9.5.0/mysql-connector-j-9.5.0.jar
MD5: f18b3756c4b8c6c2d82e3819ae085fbe
SHA1: 64153d7488bbf25c040f3b0f004177bc05b36b22
SHA256:f2ca3dfaf00d4aa311470db7ea3051962944ba0cb60005a2f75467549c39f425
Referenced In Project/Scope: Grouper UI:runtime
mysql-connector-j-9.5.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper-ui@7.0.0-SNAPSHOT

Identifiers

netty-codec-4.2.7.Final.jar

Description:

Netty is an asynchronous event-driven network application framework for    rapid development of maintainable high performance protocol servers and    clients.

License:

https://www.apache.org/licenses/LICENSE-2.0
File Path: /home/grprdist/.m2/repository/io/netty/netty-codec/4.2.7.Final/netty-codec-4.2.7.Final.jar
MD5: c25b9e14b1109d4a5ee0524933deb56c
SHA1: e47bea286fb06764f48fe7b0d96956c4faa9b4c7
SHA256:5f369658381789998c042a98f02da71d9c39884bbb4f7fd58282f765e09ca031
Referenced In Project/Scope: Grouper UI:compile
netty-codec-4.2.7.Final.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

CVE-2026-45674  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS responses. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-345 Insufficient Verification of Data Authenticity, CWE-346 Origin Validation Error

CVSSv3:
  • Base Score: CRITICAL (10.0)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-47691  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's `DnsResolveContext` insufficiently validates the bailiwick of NS records, enabling DNS Cache Poisoning. An attacker controlling an authoritative name server for a subdomain can poison the cache for parent domains (like `.co.uk`). In `io.netty.resolver.dns.DnsResolveContext.AuthoritativeNameServerList#add` method accepts any NS record from the AUTHORITY section as long as the record's name is a suffix of the questionName. Subsequently, the `handleWithAdditional` method caches the associated A records from the ADDITIONAL section directly into the `authoritativeDnsServerCache` under the parent domain's key. This bypasses standard bailiwick rules, where a server authoritative for a subdomain should not be trusted to provide authoritative records for its parent. The poisoned cache is then used for all future resolutions under the parent domain's key. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-345 Insufficient Verification of Data Authenticity, CWE-346 Origin Validation Error

CVSSv3:
  • Base Score: CRITICAL (10.0)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42581  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

CVSSv3:
  • Base Score: CRITICAL (9.8)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42579  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-20 Improper Input Validation, CWE-626 Null Byte Interaction Error (Poison Null Byte), CWE-1286 Improper Validation of Syntactic Correctness of Input

CVSSv3:
  • Base Score: CRITICAL (9.1)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42584  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

CVSSv3:
  • Base Score: CRITICAL (9.1)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-56820  

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final, `OcspClient` does not validate that the `CertificateID` in an OCSP response matches the requested `CertificateID`, which can lead to replay attack. `OcspClient.validateResponse` accepts a legitimately signed `GOOD` status response for an unrelated certificate issued by the same CA, allowing bypass of revocation checks for another certificate. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-295 Improper Certificate Validation

CVSSv3:
  • Base Score: CRITICAL (9.1)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-33871  

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv4:
  • Base Score: HIGH (8.7)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-48006  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the RedisArrayAggregator handler permanently leaks pooled direct-memory buffers when a Redis pipeline connection closes before a RESP array aggregate completes. The handler retains child messages in per-handler state (`depths` field) but defines no `channelInactive`, `handlerRemoved`, or `exceptionCaught` method to release them when the pipeline tears down. Because the leaked buffers are slices of `PooledByteBufAllocator` chunks, they prevent those chunks from being returned to the JVM-wide direct-memory pool. Repeated connection churn by any network peer monotonically drains this shared pool, eventually causing allocation failures on all Netty channels in the process. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-401 Missing Release of Memory after Effective Lifetime, CWE-772 Missing Release of Resource after Effective Lifetime

CVSSv4:
  • Base Score: HIGH (8.7)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-48059  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the HAProxy PROXY protocol v2 codec in netty leaks native or heap memory on every connection when a client sends a syntactically valid header containing nested `PP2_TYPE_SSL` TLVs (type-length-value records) at depth two or greater. The leak occurs on the successful parse path — no exception is thrown, the message fires downstream, the decoder removes itself, and the application releases the `HAProxyMessage` normally. Yet the underlying cumulation buffer (a pooled, potentially direct `ByteBuf` allocated by the channel) remains permanently pinned. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-401 Missing Release of Memory after Effective Lifetime, CWE-1286 Improper Validation of Syntactic Correctness of Input

CVSSv4:
  • Base Score: HIGH (8.7)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-55851  

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final up to (but not including) 4.2.16.Final, and 4.1.0.Final up to (but not including) 4.1.135, the `HAProxyMessageDecoder` in Netty's `codec-haproxy` module performs protocol version detection by reading the 13th byte as a signed Java `byte` and widening it to `int` without masking; a PROXY protocol v2 binary prefix followed by version byte `0xFF` sign-extends to `-1`, collides with the decoder's need-more-data sentinel, and causes `ByteToMessageDecoder` to accumulate inbound bytes in an unbounded `cumulation` buffer until direct memory is exhausted. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-400 Uncontrolled Resource Consumption

CVSSv4:
  • Base Score: HIGH (8.7)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-56745  

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, the `SpdyHttpDecoder` handler in Netty's SPDY-to-HTTP codec allocates a pooled `ByteBuf` when processing a client-initiated `SYN_STREAM` frame with `FLAG_FIN=0` and stores the partially constructed `FullHttpRequest` in `messageMap`; when the remote peer sends `RST_STREAM` for that stream or the accumulated content exceeds `maxContentLength`, the decoder removes the entry but does not release the pooled `ByteBuf`, causing native memory exhaustion. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-400 Uncontrolled Resource Consumption

CVSSv4:
  • Base Score: HIGH (8.7)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-56817  

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, any caller that can deliver bytes to a Netty channel pipeline containing `XmlDecoder` can send XML with a `DOCTYPE` declaration to an `AsyncXMLInputFactory` instantiated with no security configuration, leaving DTD and entity handling active depending on Aalto XML async parser behavior and creating conditional XML external entity risk. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-611 Improper Restriction of XML External Entity Reference

CVSSv4:
  • Base Score: HIGH (8.3)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: CRITICAL (9.8)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-44249  

Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-697 Incorrect Comparison, CWE-1287 Improper Validation of Specified Type of Input, CWE-284 Improper Access Control

CVSSv3:
  • Base Score: HIGH (8.1)
  • Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:2.2/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-33870  

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42577  

Netty is an asynchronous, event-driven network application framework. From 4.2.0.Final to 4.2.13.Final , Netty's epoll transport fails to detect and close TCP connections that receive a RST after being half-closed, leading to stale channels that are never cleaned up and, in some code paths, a 100% CPU busy-loop in the event loop thread. This vulnerability is fixed in 4.2.13.Final.
CWE-772 Missing Release of Resource after Effective Lifetime

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions:

CVE-2026-42582  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.
CWE-789 Memory Allocation with Excessive Size Value, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions:

CVE-2026-42583  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42585  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42587  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-44248  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion. This can cause high resource usage in both CPU and memory. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-44250  

Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can cause DoS by sending a crafted Redis payload with deeply nested arrays. This forces the server to allocate a massive number of state objects and collections, leading to memory exhaustion and an OutOfMemoryError. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-44890  

Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can cause DoS by sending crafted Redis payloads across multiple connections without `\r\n`. This exhausts the server's direct memory pool (OutOfDirectMemoryError), preventing legitimate connections from being processed. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-44891  

Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.stomp.StompSubframeDecoder fails to limit the total number of headers or their cumulative size per frame, and the maxLineLength parameter only restricts individual header lines. An attacker can send a large number of short headers that are accumulated in memory inside DefaultStompHeadersSubframe until the JVM throws an OutOfMemoryError, causing denial of service for servers exposing a STOMP endpoint based on StompSubframeDecoder. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-44892  

Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final, the default configuration of the `Http3ConnectionHandler` in the Netty HTTP/3 codec lacks an enforced maximum header size limit. When a peer does not explicitly specify `HTTP3_SETTINGS_MAX_FIELD_SECTION_SIZE`, the implementation defaults to an unbounded limit. This insecure default configuration allows a malicious client or server to send an enormous number of headers, leading to a memory exhaustion Denial of Service via an `OutOfMemoryError`. Version 4.2.15.Final contains a patch.
CWE-400 Uncontrolled Resource Consumption, CWE-1188 Insecure Default Initialization of Resource

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions:

CVE-2026-44893  

Netty is a network application framework for development of protocol servers and clients. In netty-codec-haproxy prior to versions 4.1.135.Final and 4.2.15.Final, when decoding a PP2_TYPE_SSL TLV, HAProxyMessage.readNextTLV() first calls `header.retainedSlice(header.readerIndex(), length)` and only then reads the 1-byte client field and 4-byte verify field. If the attacker sets the TLV length below 5, the subsequent readByte/readInt throws IndexOutOfBoundsException. HAProxyMessageDecoder only catches HAProxyProtocolException around this call, so the IOOBE propagates and the retained slice on the pooled cumulation buffer is never released. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-703 Improper Check or Handling of Exceptional Conditions, CWE-805 Buffer Access with Incorrect Length Value

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-44894  

Netty is a network application framework for development of protocol servers and clients. NoQuicTokenHandler is the tokenHandler used when the application does not set one. Prior to version 4.2.15.Final, its writeToken() returns false (server will not send Retry — acceptable), but validateToken() unconditionally `return 0`. In QuicheQuicServerCodec.handlePacket(), a non-negative return from validateToken() is interpreted as 'token is valid, ODCID starts at offset 0', causing the server to call quiche_accept as if the client's address had been validated by a Retry round-trip. Per RFC 9000 §8.1, a validated address lifts the 3× anti-amplification send limit. Thus any attacker who includes ANY non-empty token bytes in an Initial packet — with a spoofed victim source IP — causes the Netty server to treat the victim as validated and reflect full-size handshake flights (certificates, etc.) toward it without the 3× cap. The correct 'no token handler' semantics would be to return -1 (invalid) so the normal un-validated path and amplification limit apply. Version 4.2.15.Final patches the issue.
CWE-940 Improper Verification of Source of a Communication Channel, CWE-346 Origin Validation Error

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions:

CVE-2026-45416  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SslClientHelloHandler.decode() reads the 24-bit TLS handshake length and, when the ClientHello does not fit in the first record, eagerly allocates `ctx.alloc().buffer(handshakeLength)` (line 161). The guard at line 140 is `handshakeLength > maxClientHelloLength && maxClientHelloLength != 0`, and the commonly-used SniHandler/AbstractSniHandler constructors (SniHandler(Mapping), SniHandler(AsyncMapping), AbstractSniHandler()) pass maxClientHelloLength=0 and handshakeTimeoutMillis=0, so the length guard is disabled and no timeout is scheduled. A 16 MiB request exceeds the default pooled chunk size and becomes a huge/unpooled allocation performed immediately. The buffer is retained in the handler until the channel closes. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-46340  

Netty is a network application framework for development of protocol servers and clients. In versions of netty-transport-sctp prior to 4.1.135.Final and 4.2.15.Final, for each non-complete SctpMessage fragment the handler does `fragments.put(streamId, Unpooled.wrappedBuffer(frag, byteBuf))`, wrapping the previous accumulator and the new slice into a *new* CompositeByteBuf every time. After N fragments the accumulator is an N-deep chain of composites, each holding references and component arrays; readableBytes()/getBytes() on the final buffer recurse N levels. There is no limit on N, on total bytes, or on the number of streamIdentifiers an attacker can open (each gets its own map entry). A peer that never sets the `complete` flag can grow this structure indefinitely from tiny 1-byte DATA chunks. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-48043  

Netty is a network application framework for development of protocol servers and clients. In netty-codec-http2 prior to versions 4.1.135.Final and 4.2.15.Final, the `DelegatingDecompressorFrameListener` class orchestrates HTTP/2 decompression by embedding a per-stream `EmbeddedChannel` that runs the appropriate decompression codec (gzip, deflate, zstd) and forwards decompressed chunks to a wrapped listener. Each decompressed chunk is a pooled `ByteBuf` handed to an anonymous `ChannelInboundHandlerAdapter` tail handler, which becomes the sole owner responsible for releasing it. A remote peer could send frames that would result in the flow-controller throwing and so trigger a resource leak which at the end might take down the whole JVM due OOME. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-400 Uncontrolled Resource Consumption, CWE-401 Missing Release of Memory after Effective Lifetime, CWE-772 Missing Release of Resource after Effective Lifetime

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-48748  

Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final, a memory exhaustion vulnerability in the Netty HTTP/3 codec allows the creation of an infinite number of blocked streams, which can cause OOM error. Version 4.2.15.Final patches the issue.
CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions:

CVE-2026-50010  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SimpleTrustManagerFactory.engineGetTrustManagers() and related paths wrap any user-supplied plain X509TrustManager in X509TrustManagerWrapper, which extends X509ExtendedTrustManager but implements the 3-arg checkServerTrusted(chain, authType, SSLEngine) by discarding the SSLEngine and calling the 2-arg delegate. Because the object now IS an X509ExtendedTrustManager, neither SunJSSE's internal AbstractTrustManagerWrapper nor Netty's own OpenSslX509TrustManagerWrapper will re-wrap it to add endpoint-identification. Consequently, even though Netty 4.2 sets endpointIdentificationAlgorithm="HTTPS" by default, a client built with `SslContextBuilder.forClient().trustManager(somePlainX509TrustManager)` performs no hostname verification at all. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-347 Improper Verification of Cryptographic Signature

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-50011  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, RedisArrayAggregator pre-allocates ArrayList with initial capacity equal to the RESP array element count declared in an array header. That count is taken from the wire before the corresponding child messages exist. A small malicious header can claim a huge initial capacity. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-55831  

Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length limit and materializes every unique setting ID in `DefaultSpdySettingsFrame`, allowing a remote SPDY/3.1 peer to send a syntactically valid roughly 2 MiB SETTINGS frame that creates 262144 map entries and amplifies network input into heap growth and ordered-map insertion work. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-55833  

Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has exceeded `maxHeaderSize` and marked the frame truncated in `SpdyFrameCodec`, allowing a remote peer to send a small compressed `HEADERS` block that expands into much larger raw header data and causes compression-amplified CPU and allocation churn. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-400 Uncontrolled Resource Consumption

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-56816  

Netty is a network application framework for development of protocol servers and clients. Prior to 4.2.16.Final, Netty's `Http3FrameCodec` buffers incoming data for HTTP/3 reserved frame types up to the wire-specified payload length without limits; `decodeFrame` trusts `payLoadLength`, allowing an attacker to open multiple QUIC streams and send reserved frames with very large payload lengths to cause memory exhaustion and denial of service. This issue is fixed in version 4.2.16.Final.
CWE-400 Uncontrolled Resource Consumption

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions:

CVE-2026-56819  

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, a remote unauthenticated peer can leak one direct `ByteBuf` per HTTP/2 `DATA` frame in applications that enable HTTP/2 content decompression via `DelegatingDecompressorFrameListener`. When a `DATA` frame is processed for a stream whose decompressor has already been closed, `Http2Decompressor.decompress(...)` calls `decompressor.writeInbound(data.retain())` and does not release the retained buffer on the error path, eventually exhausting direct memory and crashing the JVM. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-401 Missing Release of Memory after Effective Lifetime

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42586  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')

CVSSv3:
  • Base Score: HIGH (7.1)
  • Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:1.8/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-50560  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty HTTP/2 max header size handling produces an attack similar to HTTP/2 Rapid Reset. There is a setting in the http2 specification called `SETTINGS_MAX_HEADER_LIST_SIZE`. When a client sends that setting to Netty, it appears that Netty will behave as follows: read the request; proxy the request to the origin; attempt to produce a response; and create an exception while writing the headers for the response. Functionally, this should be similar to the http2 reset attack, but with a different on-the-wire signature. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv4:
  • Base Score: MEDIUM (6.9)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: MEDIUM (5.3)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-45673  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DNS resolver uses a predictable PRNG for generating DNS transaction IDs and defaults to a static UDP source port. This combination reduces the entropy of DNS queries, enabling DNS Cache Poisoning (Kaminsky attack). Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-340 Generation of Predictable Numbers or Identifiers, CWE-330 Use of Insufficiently Random Values

CVSSv3:
  • Base Score: MEDIUM (6.8)
  • Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N/E:2.2/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2025-67735  

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')

CVSSv3:
  • Base Score: MEDIUM (6.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42580  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-190 Integer Overflow or Wraparound

CVSSv3:
  • Base Score: MEDIUM (6.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-56746  

Netty is a network application framework for development of protocol servers and clients. Versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, are vulnerable to security control bypass during the origin evaluation process. CorsHandler provides a shortCircuit() configuration designed to reject unauthorized cross-origin requests immediately, acting as a security control before requests reach the application. However, due to a logical operator error in the origin evaluation process, this protection can be entirely bypassed. An attacker can bypass the short-circuit mechanism by sending a request with an Origin: null header. This failure forwards unauthorized requests to the backend application, bypassing intended access controls. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-284 Improper Access Control

CVSSv3:
  • Base Score: MEDIUM (6.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N/E:2.8/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-41417  

Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')

CVSSv3:
  • Base Score: MEDIUM (5.3)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-47244  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, DefaultHttp2Connection.DefaultEndpoint initialises maxActiveStreams/maxStreams to Integer.MAX_VALUE, and Http2Settings never inserts SETTINGS_MAX_CONCURRENT_STREAMS by default (Http2Settings.java:305-307 only clamps a user-supplied value). Unless the application explicitly calls initialSettings().maxConcurrentStreams(n), a Netty HTTP/2 server advertises no limit and enforces none locally. Each open stream allocates a DefaultStream object, PropertyMap slots, flow-controller state and IntObjectHashMap entry; with ~2^30 permissible odd stream IDs a single TCP connection can create hundreds of thousands of long-lived stream objects. This is also the precondition for CVE-2023-44487-style Rapid-Reset amplification, where the absence of a low concurrent cap multiplies backend work. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-400 Uncontrolled Resource Consumption

CVSSv3:
  • Base Score: MEDIUM (5.3)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-50020  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, before reading the first request-line, `HttpObjectDecoder` skips every byte for which `Character.isISOControl(b)` is `true` (0x00–0x1F and 0x7F) as well as all whitespace. RFC 9112 §2.2 only asks servers to ignore empty CRLF lines preceding the request-line — a carefully scoped robustness allowance intended to handle HTTP/1.0 POST workarounds. Silently absorbing NUL bytes, SOH, STX, and other non-CRLF control characters goes significantly beyond this, and can be exploited for request-boundary confusion in pipelined or multiplexed transports where a front-end component treats those bytes differently. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

CVSSv3:
  • Base Score: MEDIUM (5.3)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-50009  

Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final, Netty QUIC exposes the stateless reset token on the network path when using the default HMAC-based connection-ID and stateless-reset-token generators. The reset token for the server's current source connection ID can be derived from bytes that appear as the connection ID in QUIC headers after a source-CID rotation. An on-path attacker observing the headers can use the token to perform a Denial of Service by sending a spoofed Stateless Reset packet. Version 4.2.15.Final patches the issue.
CWE-330 Use of Insufficiently Random Values, CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

CVSSv3:
  • Base Score: MEDIUM (4.8)
  • Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L/E:2.2/RC:R/MAV:A

References:

Vulnerable Software & Versions:

CVE-2026-45536  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, netty_unix_socket_recvFd sets msg_control to `char control[CMSG_SPACE(sizeof(int))]` (line 940) — 24 bytes on 64-bit Linux. A peer-sent SCM_RIGHTS cmsg carrying two ints has cmsg_len = CMSG_LEN(8) = 24, which fits exactly with no MSG_CTRUNC, so the kernel installs both fds in the receiving process. The subsequent check `cmsg->cmsg_len == CMSG_LEN(sizeof(int))` (line 972, expected 20) fails, the branch that would read the fd is skipped, and neither installed fd is closed. The for(;;) loop calls recvmsg again (non-blocking → EAGAIN → Java maps to 0 → read loop exits normally), leaving two leaked fds per message. There is no MSG_CTRUNC handling. Reachable via Epoll/KQueue DomainSocketChannel when the application opts into DomainSocketReadMode.FILE_DESCRIPTORS (non-default). Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor, CWE-772 Missing Release of Resource after Effective Lifetime

CVSSv3:
  • Base Score: MEDIUM (4.0)
  • Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:2.5/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42578  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection'), CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')

CVSSv4:
  • Base Score: LOW (2.9)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

netty-codec-compression-4.2.7.Final.jar

Description:

Netty is an asynchronous event-driven network application framework for    rapid development of maintainable high performance protocol servers and    clients.

License:

https://www.apache.org/licenses/LICENSE-2.0
File Path: /home/grprdist/.m2/repository/io/netty/netty-codec-compression/4.2.7.Final/netty-codec-compression-4.2.7.Final.jar
MD5: d7df10ca556335a43abfa4e5e848b5b1
SHA1: 572341bc1ca90fd9d6e47f1d2694aab5258566e9
SHA256:edd53ad34991804301a46571113d8ffb4d6f67e6d874674dafbb915724275cb3
Referenced In Project/Scope: Grouper UI:compile
netty-codec-compression-4.2.7.Final.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

CVE-2026-45674  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS responses. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-345 Insufficient Verification of Data Authenticity, CWE-346 Origin Validation Error

CVSSv3:
  • Base Score: CRITICAL (10.0)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-47691  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's `DnsResolveContext` insufficiently validates the bailiwick of NS records, enabling DNS Cache Poisoning. An attacker controlling an authoritative name server for a subdomain can poison the cache for parent domains (like `.co.uk`). In `io.netty.resolver.dns.DnsResolveContext.AuthoritativeNameServerList#add` method accepts any NS record from the AUTHORITY section as long as the record's name is a suffix of the questionName. Subsequently, the `handleWithAdditional` method caches the associated A records from the ADDITIONAL section directly into the `authoritativeDnsServerCache` under the parent domain's key. This bypasses standard bailiwick rules, where a server authoritative for a subdomain should not be trusted to provide authoritative records for its parent. The poisoned cache is then used for all future resolutions under the parent domain's key. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-345 Insufficient Verification of Data Authenticity, CWE-346 Origin Validation Error

CVSSv3:
  • Base Score: CRITICAL (10.0)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42581  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

CVSSv3:
  • Base Score: CRITICAL (9.8)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42579  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-20 Improper Input Validation, CWE-626 Null Byte Interaction Error (Poison Null Byte), CWE-1286 Improper Validation of Syntactic Correctness of Input

CVSSv3:
  • Base Score: CRITICAL (9.1)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42584  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

CVSSv3:
  • Base Score: CRITICAL (9.1)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-56820  

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final, `OcspClient` does not validate that the `CertificateID` in an OCSP response matches the requested `CertificateID`, which can lead to replay attack. `OcspClient.validateResponse` accepts a legitimately signed `GOOD` status response for an unrelated certificate issued by the same CA, allowing bypass of revocation checks for another certificate. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-295 Improper Certificate Validation

CVSSv3:
  • Base Score: CRITICAL (9.1)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-33871  

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv4:
  • Base Score: HIGH (8.7)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-48006  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the RedisArrayAggregator handler permanently leaks pooled direct-memory buffers when a Redis pipeline connection closes before a RESP array aggregate completes. The handler retains child messages in per-handler state (`depths` field) but defines no `channelInactive`, `handlerRemoved`, or `exceptionCaught` method to release them when the pipeline tears down. Because the leaked buffers are slices of `PooledByteBufAllocator` chunks, they prevent those chunks from being returned to the JVM-wide direct-memory pool. Repeated connection churn by any network peer monotonically drains this shared pool, eventually causing allocation failures on all Netty channels in the process. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-401 Missing Release of Memory after Effective Lifetime, CWE-772 Missing Release of Resource after Effective Lifetime

CVSSv4:
  • Base Score: HIGH (8.7)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-48059  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the HAProxy PROXY protocol v2 codec in netty leaks native or heap memory on every connection when a client sends a syntactically valid header containing nested `PP2_TYPE_SSL` TLVs (type-length-value records) at depth two or greater. The leak occurs on the successful parse path — no exception is thrown, the message fires downstream, the decoder removes itself, and the application releases the `HAProxyMessage` normally. Yet the underlying cumulation buffer (a pooled, potentially direct `ByteBuf` allocated by the channel) remains permanently pinned. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-401 Missing Release of Memory after Effective Lifetime, CWE-1286 Improper Validation of Syntactic Correctness of Input

CVSSv4:
  • Base Score: HIGH (8.7)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-55851  

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final up to (but not including) 4.2.16.Final, and 4.1.0.Final up to (but not including) 4.1.135, the `HAProxyMessageDecoder` in Netty's `codec-haproxy` module performs protocol version detection by reading the 13th byte as a signed Java `byte` and widening it to `int` without masking; a PROXY protocol v2 binary prefix followed by version byte `0xFF` sign-extends to `-1`, collides with the decoder's need-more-data sentinel, and causes `ByteToMessageDecoder` to accumulate inbound bytes in an unbounded `cumulation` buffer until direct memory is exhausted. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-400 Uncontrolled Resource Consumption

CVSSv4:
  • Base Score: HIGH (8.7)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-56745  

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, the `SpdyHttpDecoder` handler in Netty's SPDY-to-HTTP codec allocates a pooled `ByteBuf` when processing a client-initiated `SYN_STREAM` frame with `FLAG_FIN=0` and stores the partially constructed `FullHttpRequest` in `messageMap`; when the remote peer sends `RST_STREAM` for that stream or the accumulated content exceeds `maxContentLength`, the decoder removes the entry but does not release the pooled `ByteBuf`, causing native memory exhaustion. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-400 Uncontrolled Resource Consumption

CVSSv4:
  • Base Score: HIGH (8.7)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-59901 (OSSINDEX)  

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the `Bzip2Decoder` handler in Netty's compression codec pipeline is vulnerable to a denial-of-service attack through a malformed bzip2 stream that permanently captures the event-loop thread in an infinite loop. The vulnerability exists in the run-length encoding (RLE) state machine within [`Bzip2BlockDecompressor.read()`]. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')

CVSSv2:
  • Base Score: HIGH (8.699999809265137)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

References:

Vulnerable Software & Versions (OSSINDEX):

  • cpe:2.3:a:io.netty:netty-codec-compression:4.2.7.Final:*:*:*:*:*:*:*

CVE-2026-56817  

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, any caller that can deliver bytes to a Netty channel pipeline containing `XmlDecoder` can send XML with a `DOCTYPE` declaration to an `AsyncXMLInputFactory` instantiated with no security configuration, leaving DTD and entity handling active depending on Aalto XML async parser behavior and creating conditional XML external entity risk. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-611 Improper Restriction of XML External Entity Reference

CVSSv4:
  • Base Score: HIGH (8.3)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: CRITICAL (9.8)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-44249  

Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-697 Incorrect Comparison, CWE-1287 Improper Validation of Specified Type of Input, CWE-284 Improper Access Control

CVSSv3:
  • Base Score: HIGH (8.1)
  • Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:2.2/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-33870  

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42577  

Netty is an asynchronous, event-driven network application framework. From 4.2.0.Final to 4.2.13.Final , Netty's epoll transport fails to detect and close TCP connections that receive a RST after being half-closed, leading to stale channels that are never cleaned up and, in some code paths, a 100% CPU busy-loop in the event loop thread. This vulnerability is fixed in 4.2.13.Final.
CWE-772 Missing Release of Resource after Effective Lifetime

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions:

CVE-2026-42582  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.
CWE-789 Memory Allocation with Excessive Size Value, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions:

CVE-2026-42583  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42585  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42587  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-44248  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion. This can cause high resource usage in both CPU and memory. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-44250  

Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can cause DoS by sending a crafted Redis payload with deeply nested arrays. This forces the server to allocate a massive number of state objects and collections, leading to memory exhaustion and an OutOfMemoryError. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-44890  

Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can cause DoS by sending crafted Redis payloads across multiple connections without `\r\n`. This exhausts the server's direct memory pool (OutOfDirectMemoryError), preventing legitimate connections from being processed. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-44891  

Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.stomp.StompSubframeDecoder fails to limit the total number of headers or their cumulative size per frame, and the maxLineLength parameter only restricts individual header lines. An attacker can send a large number of short headers that are accumulated in memory inside DefaultStompHeadersSubframe until the JVM throws an OutOfMemoryError, causing denial of service for servers exposing a STOMP endpoint based on StompSubframeDecoder. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-44892  

Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final, the default configuration of the `Http3ConnectionHandler` in the Netty HTTP/3 codec lacks an enforced maximum header size limit. When a peer does not explicitly specify `HTTP3_SETTINGS_MAX_FIELD_SECTION_SIZE`, the implementation defaults to an unbounded limit. This insecure default configuration allows a malicious client or server to send an enormous number of headers, leading to a memory exhaustion Denial of Service via an `OutOfMemoryError`. Version 4.2.15.Final contains a patch.
CWE-400 Uncontrolled Resource Consumption, CWE-1188 Insecure Default Initialization of Resource

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions:

CVE-2026-44893  

Netty is a network application framework for development of protocol servers and clients. In netty-codec-haproxy prior to versions 4.1.135.Final and 4.2.15.Final, when decoding a PP2_TYPE_SSL TLV, HAProxyMessage.readNextTLV() first calls `header.retainedSlice(header.readerIndex(), length)` and only then reads the 1-byte client field and 4-byte verify field. If the attacker sets the TLV length below 5, the subsequent readByte/readInt throws IndexOutOfBoundsException. HAProxyMessageDecoder only catches HAProxyProtocolException around this call, so the IOOBE propagates and the retained slice on the pooled cumulation buffer is never released. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-703 Improper Check or Handling of Exceptional Conditions, CWE-805 Buffer Access with Incorrect Length Value

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-44894  

Netty is a network application framework for development of protocol servers and clients. NoQuicTokenHandler is the tokenHandler used when the application does not set one. Prior to version 4.2.15.Final, its writeToken() returns false (server will not send Retry — acceptable), but validateToken() unconditionally `return 0`. In QuicheQuicServerCodec.handlePacket(), a non-negative return from validateToken() is interpreted as 'token is valid, ODCID starts at offset 0', causing the server to call quiche_accept as if the client's address had been validated by a Retry round-trip. Per RFC 9000 §8.1, a validated address lifts the 3× anti-amplification send limit. Thus any attacker who includes ANY non-empty token bytes in an Initial packet — with a spoofed victim source IP — causes the Netty server to treat the victim as validated and reflect full-size handshake flights (certificates, etc.) toward it without the 3× cap. The correct 'no token handler' semantics would be to return -1 (invalid) so the normal un-validated path and amplification limit apply. Version 4.2.15.Final patches the issue.
CWE-940 Improper Verification of Source of a Communication Channel, CWE-346 Origin Validation Error

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions:

CVE-2026-45416  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SslClientHelloHandler.decode() reads the 24-bit TLS handshake length and, when the ClientHello does not fit in the first record, eagerly allocates `ctx.alloc().buffer(handshakeLength)` (line 161). The guard at line 140 is `handshakeLength > maxClientHelloLength && maxClientHelloLength != 0`, and the commonly-used SniHandler/AbstractSniHandler constructors (SniHandler(Mapping), SniHandler(AsyncMapping), AbstractSniHandler()) pass maxClientHelloLength=0 and handshakeTimeoutMillis=0, so the length guard is disabled and no timeout is scheduled. A 16 MiB request exceeds the default pooled chunk size and becomes a huge/unpooled allocation performed immediately. The buffer is retained in the handler until the channel closes. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-46340  

Netty is a network application framework for development of protocol servers and clients. In versions of netty-transport-sctp prior to 4.1.135.Final and 4.2.15.Final, for each non-complete SctpMessage fragment the handler does `fragments.put(streamId, Unpooled.wrappedBuffer(frag, byteBuf))`, wrapping the previous accumulator and the new slice into a *new* CompositeByteBuf every time. After N fragments the accumulator is an N-deep chain of composites, each holding references and component arrays; readableBytes()/getBytes() on the final buffer recurse N levels. There is no limit on N, on total bytes, or on the number of streamIdentifiers an attacker can open (each gets its own map entry). A peer that never sets the `complete` flag can grow this structure indefinitely from tiny 1-byte DATA chunks. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-48043  

Netty is a network application framework for development of protocol servers and clients. In netty-codec-http2 prior to versions 4.1.135.Final and 4.2.15.Final, the `DelegatingDecompressorFrameListener` class orchestrates HTTP/2 decompression by embedding a per-stream `EmbeddedChannel` that runs the appropriate decompression codec (gzip, deflate, zstd) and forwards decompressed chunks to a wrapped listener. Each decompressed chunk is a pooled `ByteBuf` handed to an anonymous `ChannelInboundHandlerAdapter` tail handler, which becomes the sole owner responsible for releasing it. A remote peer could send frames that would result in the flow-controller throwing and so trigger a resource leak which at the end might take down the whole JVM due OOME. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-400 Uncontrolled Resource Consumption, CWE-401 Missing Release of Memory after Effective Lifetime, CWE-772 Missing Release of Resource after Effective Lifetime

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-48748  

Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final, a memory exhaustion vulnerability in the Netty HTTP/3 codec allows the creation of an infinite number of blocked streams, which can cause OOM error. Version 4.2.15.Final patches the issue.
CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions:

CVE-2026-50010  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SimpleTrustManagerFactory.engineGetTrustManagers() and related paths wrap any user-supplied plain X509TrustManager in X509TrustManagerWrapper, which extends X509ExtendedTrustManager but implements the 3-arg checkServerTrusted(chain, authType, SSLEngine) by discarding the SSLEngine and calling the 2-arg delegate. Because the object now IS an X509ExtendedTrustManager, neither SunJSSE's internal AbstractTrustManagerWrapper nor Netty's own OpenSslX509TrustManagerWrapper will re-wrap it to add endpoint-identification. Consequently, even though Netty 4.2 sets endpointIdentificationAlgorithm="HTTPS" by default, a client built with `SslContextBuilder.forClient().trustManager(somePlainX509TrustManager)` performs no hostname verification at all. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-347 Improper Verification of Cryptographic Signature

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-50011  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, RedisArrayAggregator pre-allocates ArrayList with initial capacity equal to the RESP array element count declared in an array header. That count is taken from the wire before the corresponding child messages exist. A small malicious header can claim a huge initial capacity. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-55831  

Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length limit and materializes every unique setting ID in `DefaultSpdySettingsFrame`, allowing a remote SPDY/3.1 peer to send a syntactically valid roughly 2 MiB SETTINGS frame that creates 262144 map entries and amplifies network input into heap growth and ordered-map insertion work. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-55833  

Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has exceeded `maxHeaderSize` and marked the frame truncated in `SpdyFrameCodec`, allowing a remote peer to send a small compressed `HEADERS` block that expands into much larger raw header data and causes compression-amplified CPU and allocation churn. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-400 Uncontrolled Resource Consumption

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-56816  

Netty is a network application framework for development of protocol servers and clients. Prior to 4.2.16.Final, Netty's `Http3FrameCodec` buffers incoming data for HTTP/3 reserved frame types up to the wire-specified payload length without limits; `decodeFrame` trusts `payLoadLength`, allowing an attacker to open multiple QUIC streams and send reserved frames with very large payload lengths to cause memory exhaustion and denial of service. This issue is fixed in version 4.2.16.Final.
CWE-400 Uncontrolled Resource Consumption

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions:

CVE-2026-56819  

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, a remote unauthenticated peer can leak one direct `ByteBuf` per HTTP/2 `DATA` frame in applications that enable HTTP/2 content decompression via `DelegatingDecompressorFrameListener`. When a `DATA` frame is processed for a stream whose decompressor has already been closed, `Http2Decompressor.decompress(...)` calls `decompressor.writeInbound(data.retain())` and does not release the retained buffer on the error path, eventually exhausting direct memory and crashing the JVM. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-401 Missing Release of Memory after Effective Lifetime

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42586  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')

CVSSv3:
  • Base Score: HIGH (7.1)
  • Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:1.8/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-50560  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty HTTP/2 max header size handling produces an attack similar to HTTP/2 Rapid Reset. There is a setting in the http2 specification called `SETTINGS_MAX_HEADER_LIST_SIZE`. When a client sends that setting to Netty, it appears that Netty will behave as follows: read the request; proxy the request to the origin; attempt to produce a response; and create an exception while writing the headers for the response. Functionally, this should be similar to the http2 reset attack, but with a different on-the-wire signature. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv4:
  • Base Score: MEDIUM (6.9)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: MEDIUM (5.3)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-45673  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DNS resolver uses a predictable PRNG for generating DNS transaction IDs and defaults to a static UDP source port. This combination reduces the entropy of DNS queries, enabling DNS Cache Poisoning (Kaminsky attack). Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-340 Generation of Predictable Numbers or Identifiers, CWE-330 Use of Insufficiently Random Values

CVSSv3:
  • Base Score: MEDIUM (6.8)
  • Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N/E:2.2/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2025-67735  

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')

CVSSv3:
  • Base Score: MEDIUM (6.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42580  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-190 Integer Overflow or Wraparound

CVSSv3:
  • Base Score: MEDIUM (6.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-56746  

Netty is a network application framework for development of protocol servers and clients. Versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, are vulnerable to security control bypass during the origin evaluation process. CorsHandler provides a shortCircuit() configuration designed to reject unauthorized cross-origin requests immediately, acting as a security control before requests reach the application. However, due to a logical operator error in the origin evaluation process, this protection can be entirely bypassed. An attacker can bypass the short-circuit mechanism by sending a request with an Origin: null header. This failure forwards unauthorized requests to the backend application, bypassing intended access controls. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-284 Improper Access Control

CVSSv3:
  • Base Score: MEDIUM (6.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N/E:2.8/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-41417  

Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')

CVSSv3:
  • Base Score: MEDIUM (5.3)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-47244  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, DefaultHttp2Connection.DefaultEndpoint initialises maxActiveStreams/maxStreams to Integer.MAX_VALUE, and Http2Settings never inserts SETTINGS_MAX_CONCURRENT_STREAMS by default (Http2Settings.java:305-307 only clamps a user-supplied value). Unless the application explicitly calls initialSettings().maxConcurrentStreams(n), a Netty HTTP/2 server advertises no limit and enforces none locally. Each open stream allocates a DefaultStream object, PropertyMap slots, flow-controller state and IntObjectHashMap entry; with ~2^30 permissible odd stream IDs a single TCP connection can create hundreds of thousands of long-lived stream objects. This is also the precondition for CVE-2023-44487-style Rapid-Reset amplification, where the absence of a low concurrent cap multiplies backend work. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-400 Uncontrolled Resource Consumption

CVSSv3:
  • Base Score: MEDIUM (5.3)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-50020  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, before reading the first request-line, `HttpObjectDecoder` skips every byte for which `Character.isISOControl(b)` is `true` (0x00–0x1F and 0x7F) as well as all whitespace. RFC 9112 §2.2 only asks servers to ignore empty CRLF lines preceding the request-line — a carefully scoped robustness allowance intended to handle HTTP/1.0 POST workarounds. Silently absorbing NUL bytes, SOH, STX, and other non-CRLF control characters goes significantly beyond this, and can be exploited for request-boundary confusion in pipelined or multiplexed transports where a front-end component treats those bytes differently. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

CVSSv3:
  • Base Score: MEDIUM (5.3)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-50009  

Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final, Netty QUIC exposes the stateless reset token on the network path when using the default HMAC-based connection-ID and stateless-reset-token generators. The reset token for the server's current source connection ID can be derived from bytes that appear as the connection ID in QUIC headers after a source-CID rotation. An on-path attacker observing the headers can use the token to perform a Denial of Service by sending a spoofed Stateless Reset packet. Version 4.2.15.Final patches the issue.
CWE-330 Use of Insufficiently Random Values, CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

CVSSv3:
  • Base Score: MEDIUM (4.8)
  • Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L/E:2.2/RC:R/MAV:A

References:

Vulnerable Software & Versions:

CVE-2026-45536  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, netty_unix_socket_recvFd sets msg_control to `char control[CMSG_SPACE(sizeof(int))]` (line 940) — 24 bytes on 64-bit Linux. A peer-sent SCM_RIGHTS cmsg carrying two ints has cmsg_len = CMSG_LEN(8) = 24, which fits exactly with no MSG_CTRUNC, so the kernel installs both fds in the receiving process. The subsequent check `cmsg->cmsg_len == CMSG_LEN(sizeof(int))` (line 972, expected 20) fails, the branch that would read the fd is skipped, and neither installed fd is closed. The for(;;) loop calls recvmsg again (non-blocking → EAGAIN → Java maps to 0 → read loop exits normally), leaving two leaked fds per message. There is no MSG_CTRUNC handling. Reachable via Epoll/KQueue DomainSocketChannel when the application opts into DomainSocketReadMode.FILE_DESCRIPTORS (non-default). Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor, CWE-772 Missing Release of Resource after Effective Lifetime

CVSSv3:
  • Base Score: MEDIUM (4.0)
  • Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:2.5/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42578  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection'), CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')

CVSSv4:
  • Base Score: LOW (2.9)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

netty-codec-http-4.1.72.Final.jar

Description:

Netty is an asynchronous event-driven network application framework for    rapid development of maintainable high performance protocol servers and    clients.

License:

https://www.apache.org/licenses/LICENSE-2.0
File Path: /home/grprdist/.m2/repository/io/netty/netty-codec-http/4.1.72.Final/netty-codec-http-4.1.72.Final.jar
MD5: 299f0a5309cdd6b88c370a0c3d52ee4d
SHA1: a8f062d67303a5e4b2bc2ad48fb4fd8c99108e45
SHA256:fa6fec88010bfaf6a7415b5364671b6b18ffb6b35a986ab97b423fd8c3a0174b
Referenced In Project/Scope: Grouper UI:compile
netty-codec-http-4.1.72.Final.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

CVE-2026-45674  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS responses. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-345 Insufficient Verification of Data Authenticity, CWE-346 Origin Validation Error

CVSSv3:
  • Base Score: CRITICAL (10.0)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-47691  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's `DnsResolveContext` insufficiently validates the bailiwick of NS records, enabling DNS Cache Poisoning. An attacker controlling an authoritative name server for a subdomain can poison the cache for parent domains (like `.co.uk`). In `io.netty.resolver.dns.DnsResolveContext.AuthoritativeNameServerList#add` method accepts any NS record from the AUTHORITY section as long as the record's name is a suffix of the questionName. Subsequently, the `handleWithAdditional` method caches the associated A records from the ADDITIONAL section directly into the `authoritativeDnsServerCache` under the parent domain's key. This bypasses standard bailiwick rules, where a server authoritative for a subdomain should not be trusted to provide authoritative records for its parent. The poisoned cache is then used for all future resolutions under the parent domain's key. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-345 Insufficient Verification of Data Authenticity, CWE-346 Origin Validation Error

CVSSv3:
  • Base Score: CRITICAL (10.0)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42581  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

CVSSv3:
  • Base Score: CRITICAL (9.8)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42579  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-20 Improper Input Validation, CWE-626 Null Byte Interaction Error (Poison Null Byte), CWE-1286 Improper Validation of Syntactic Correctness of Input

CVSSv3:
  • Base Score: CRITICAL (9.1)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42584  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

CVSSv3:
  • Base Score: CRITICAL (9.1)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-56820  

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final, `OcspClient` does not validate that the `CertificateID` in an OCSP response matches the requested `CertificateID`, which can lead to replay attack. `OcspClient.validateResponse` accepts a legitimately signed `GOOD` status response for an unrelated certificate issued by the same CA, allowing bypass of revocation checks for another certificate. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-295 Improper Certificate Validation

CVSSv3:
  • Base Score: CRITICAL (9.1)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-33871  

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv4:
  • Base Score: HIGH (8.7)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-48006  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the RedisArrayAggregator handler permanently leaks pooled direct-memory buffers when a Redis pipeline connection closes before a RESP array aggregate completes. The handler retains child messages in per-handler state (`depths` field) but defines no `channelInactive`, `handlerRemoved`, or `exceptionCaught` method to release them when the pipeline tears down. Because the leaked buffers are slices of `PooledByteBufAllocator` chunks, they prevent those chunks from being returned to the JVM-wide direct-memory pool. Repeated connection churn by any network peer monotonically drains this shared pool, eventually causing allocation failures on all Netty channels in the process. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-401 Missing Release of Memory after Effective Lifetime, CWE-772 Missing Release of Resource after Effective Lifetime

CVSSv4:
  • Base Score: HIGH (8.7)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-48059  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the HAProxy PROXY protocol v2 codec in netty leaks native or heap memory on every connection when a client sends a syntactically valid header containing nested `PP2_TYPE_SSL` TLVs (type-length-value records) at depth two or greater. The leak occurs on the successful parse path — no exception is thrown, the message fires downstream, the decoder removes itself, and the application releases the `HAProxyMessage` normally. Yet the underlying cumulation buffer (a pooled, potentially direct `ByteBuf` allocated by the channel) remains permanently pinned. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-401 Missing Release of Memory after Effective Lifetime, CWE-1286 Improper Validation of Syntactic Correctness of Input

CVSSv4:
  • Base Score: HIGH (8.7)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-55851  

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final up to (but not including) 4.2.16.Final, and 4.1.0.Final up to (but not including) 4.1.135, the `HAProxyMessageDecoder` in Netty's `codec-haproxy` module performs protocol version detection by reading the 13th byte as a signed Java `byte` and widening it to `int` without masking; a PROXY protocol v2 binary prefix followed by version byte `0xFF` sign-extends to `-1`, collides with the decoder's need-more-data sentinel, and causes `ByteToMessageDecoder` to accumulate inbound bytes in an unbounded `cumulation` buffer until direct memory is exhausted. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-400 Uncontrolled Resource Consumption

CVSSv4:
  • Base Score: HIGH (8.7)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-56745  

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, the `SpdyHttpDecoder` handler in Netty's SPDY-to-HTTP codec allocates a pooled `ByteBuf` when processing a client-initiated `SYN_STREAM` frame with `FLAG_FIN=0` and stores the partially constructed `FullHttpRequest` in `messageMap`; when the remote peer sends `RST_STREAM` for that stream or the accumulated content exceeds `maxContentLength`, the decoder removes the entry but does not release the pooled `ByteBuf`, causing native memory exhaustion. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-400 Uncontrolled Resource Consumption

CVSSv4:
  • Base Score: HIGH (8.7)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-56817  

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, any caller that can deliver bytes to a Netty channel pipeline containing `XmlDecoder` can send XML with a `DOCTYPE` declaration to an `AsyncXMLInputFactory` instantiated with no security configuration, leaving DTD and entity handling active depending on Aalto XML async parser behavior and creating conditional XML external entity risk. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-611 Improper Restriction of XML External Entity Reference

CVSSv4:
  • Base Score: HIGH (8.3)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: CRITICAL (9.8)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2025-55163  

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.124.Final and 4.2.4.Final, Netty is vulnerable to MadeYouReset DDoS. This is a logical vulnerability in the HTTP/2 protocol, that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit - which results in resource exhaustion and distributed denial of service. This issue has been patched in versions 4.1.124.Final and 4.2.4.Final.
CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv4:
  • Base Score: HIGH (8.2)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-44249  

Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-697 Incorrect Comparison, CWE-1287 Improper Validation of Specified Type of Input, CWE-284 Improper Access Control

CVSSv3:
  • Base Score: HIGH (8.1)
  • Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:2.2/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2022-41881  

Netty project is an event-driven asynchronous network application framework. In versions prior to 4.1.86.Final, a StackOverflowError can be raised when parsing a malformed crafted message due to an infinite recursion. This issue is patched in version 4.1.86.Final. There is no workaround, except using a custom HaProxyMessageDecoder.
CWE-674 Uncontrolled Recursion

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions:

CVE-2023-44487  

CISA Known Exploited Vulnerability:
  • Product: IETF HTTP/2
  • Name: HTTP/2 Rapid Reset Attack Vulnerability
  • Date Added: 2023-10-10
  • Description: HTTP/2 contains a rapid reset vulnerability that allows for a distributed denial-of-service attack (DDoS).
  • Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
  • Due Date: 2023-10-31
  • Notes: This vulnerability affects a common open-source component, third-party library, or protocol used by different products. For more information, please see: HTTP/2 Rapid Reset Vulnerability, CVE-2023-44487 | CISA: https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487; https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/; https://nvd.nist.gov/vuln/detail/CVE-2023-44487

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CWE-400 Uncontrolled Resource Consumption, NVD-CWE-noinfo

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-33870  

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42583  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42585  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42587  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-44248  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion. This can cause high resource usage in both CPU and memory. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-44250  

Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can cause DoS by sending a crafted Redis payload with deeply nested arrays. This forces the server to allocate a massive number of state objects and collections, leading to memory exhaustion and an OutOfMemoryError. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-44890  

Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can cause DoS by sending crafted Redis payloads across multiple connections without `\r\n`. This exhausts the server's direct memory pool (OutOfDirectMemoryError), preventing legitimate connections from being processed. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-44891  

Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.stomp.StompSubframeDecoder fails to limit the total number of headers or their cumulative size per frame, and the maxLineLength parameter only restricts individual header lines. An attacker can send a large number of short headers that are accumulated in memory inside DefaultStompHeadersSubframe until the JVM throws an OutOfMemoryError, causing denial of service for servers exposing a STOMP endpoint based on StompSubframeDecoder. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-44893  

Netty is a network application framework for development of protocol servers and clients. In netty-codec-haproxy prior to versions 4.1.135.Final and 4.2.15.Final, when decoding a PP2_TYPE_SSL TLV, HAProxyMessage.readNextTLV() first calls `header.retainedSlice(header.readerIndex(), length)` and only then reads the 1-byte client field and 4-byte verify field. If the attacker sets the TLV length below 5, the subsequent readByte/readInt throws IndexOutOfBoundsException. HAProxyMessageDecoder only catches HAProxyProtocolException around this call, so the IOOBE propagates and the retained slice on the pooled cumulation buffer is never released. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-703 Improper Check or Handling of Exceptional Conditions, CWE-805 Buffer Access with Incorrect Length Value

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-45416  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SslClientHelloHandler.decode() reads the 24-bit TLS handshake length and, when the ClientHello does not fit in the first record, eagerly allocates `ctx.alloc().buffer(handshakeLength)` (line 161). The guard at line 140 is `handshakeLength > maxClientHelloLength && maxClientHelloLength != 0`, and the commonly-used SniHandler/AbstractSniHandler constructors (SniHandler(Mapping), SniHandler(AsyncMapping), AbstractSniHandler()) pass maxClientHelloLength=0 and handshakeTimeoutMillis=0, so the length guard is disabled and no timeout is scheduled. A 16 MiB request exceeds the default pooled chunk size and becomes a huge/unpooled allocation performed immediately. The buffer is retained in the handler until the channel closes. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-46340  

Netty is a network application framework for development of protocol servers and clients. In versions of netty-transport-sctp prior to 4.1.135.Final and 4.2.15.Final, for each non-complete SctpMessage fragment the handler does `fragments.put(streamId, Unpooled.wrappedBuffer(frag, byteBuf))`, wrapping the previous accumulator and the new slice into a *new* CompositeByteBuf every time. After N fragments the accumulator is an N-deep chain of composites, each holding references and component arrays; readableBytes()/getBytes() on the final buffer recurse N levels. There is no limit on N, on total bytes, or on the number of streamIdentifiers an attacker can open (each gets its own map entry). A peer that never sets the `complete` flag can grow this structure indefinitely from tiny 1-byte DATA chunks. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-48043  

Netty is a network application framework for development of protocol servers and clients. In netty-codec-http2 prior to versions 4.1.135.Final and 4.2.15.Final, the `DelegatingDecompressorFrameListener` class orchestrates HTTP/2 decompression by embedding a per-stream `EmbeddedChannel` that runs the appropriate decompression codec (gzip, deflate, zstd) and forwards decompressed chunks to a wrapped listener. Each decompressed chunk is a pooled `ByteBuf` handed to an anonymous `ChannelInboundHandlerAdapter` tail handler, which becomes the sole owner responsible for releasing it. A remote peer could send frames that would result in the flow-controller throwing and so trigger a resource leak which at the end might take down the whole JVM due OOME. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-400 Uncontrolled Resource Consumption, CWE-401 Missing Release of Memory after Effective Lifetime, CWE-772 Missing Release of Resource after Effective Lifetime

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-50010  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SimpleTrustManagerFactory.engineGetTrustManagers() and related paths wrap any user-supplied plain X509TrustManager in X509TrustManagerWrapper, which extends X509ExtendedTrustManager but implements the 3-arg checkServerTrusted(chain, authType, SSLEngine) by discarding the SSLEngine and calling the 2-arg delegate. Because the object now IS an X509ExtendedTrustManager, neither SunJSSE's internal AbstractTrustManagerWrapper nor Netty's own OpenSslX509TrustManagerWrapper will re-wrap it to add endpoint-identification. Consequently, even though Netty 4.2 sets endpointIdentificationAlgorithm="HTTPS" by default, a client built with `SslContextBuilder.forClient().trustManager(somePlainX509TrustManager)` performs no hostname verification at all. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-347 Improper Verification of Cryptographic Signature

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-50011  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, RedisArrayAggregator pre-allocates ArrayList with initial capacity equal to the RESP array element count declared in an array header. That count is taken from the wire before the corresponding child messages exist. A small malicious header can claim a huge initial capacity. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-55831  

Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length limit and materializes every unique setting ID in `DefaultSpdySettingsFrame`, allowing a remote SPDY/3.1 peer to send a syntactically valid roughly 2 MiB SETTINGS frame that creates 262144 map entries and amplifies network input into heap growth and ordered-map insertion work. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-55833  

Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has exceeded `maxHeaderSize` and marked the frame truncated in `SpdyFrameCodec`, allowing a remote peer to send a small compressed `HEADERS` block that expands into much larger raw header data and causes compression-amplified CPU and allocation churn. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-400 Uncontrolled Resource Consumption

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-56816  

Netty is a network application framework for development of protocol servers and clients. Prior to 4.2.16.Final, Netty's `Http3FrameCodec` buffers incoming data for HTTP/3 reserved frame types up to the wire-specified payload length without limits; `decodeFrame` trusts `payLoadLength`, allowing an attacker to open multiple QUIC streams and send reserved frames with very large payload lengths to cause memory exhaustion and denial of service. This issue is fixed in version 4.2.16.Final.
CWE-400 Uncontrolled Resource Consumption

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions:

CVE-2026-56819  

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, a remote unauthenticated peer can leak one direct `ByteBuf` per HTTP/2 `DATA` frame in applications that enable HTTP/2 content decompression via `DelegatingDecompressorFrameListener`. When a `DATA` frame is processed for a stream whose decompressor has already been closed, `Http2Decompressor.decompress(...)` calls `decompressor.writeInbound(data.retain())` and does not release the retained buffer on the error path, eventually exhausting direct memory and crashing the JVM. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-401 Missing Release of Memory after Effective Lifetime

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42586  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')

CVSSv3:
  • Base Score: HIGH (7.1)
  • Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:1.8/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-59899 (OSSINDEX)  

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, `HttpContentEncoder` (the superclass of the production handler `HttpContentCompressor`) maintains a per-channel `ArrayDeque<CharSequence>` named `acceptEncodingQueue` that accumulates attacker-controlled data without any size limit. The queue is filled on the I/O thread for every inbound HTTP request and drained only when the application later writes a non-1xx response. This creates a resource exhaustion vulnerability when an attacker exploits HTTP/1.1 pipelining to flood the connection with requests faster than the application produces responses. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv2:
  • Base Score: MEDIUM (6.900000095367432)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

References:

Vulnerable Software & Versions (OSSINDEX):

  • cpe:2.3:a:io.netty:netty-codec-http:4.1.72.Final:*:*:*:*:*:*:*

CVE-2025-58057  

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In netty-codec-compression versions 4.1.124.Final and below, and netty-codec versions 4.2.4.Final and below, when supplied with specially crafted input, BrotliDecoder and certain other decompression decoders will allocate a large number of reachable byte buffers, which can lead to denial of service. BrotliDecoder.decompress has no limit in how often it calls pull, decompressing data 64K bytes at a time. The buffers are saved in the output list, and remain reachable until OOM is hit. This is fixed in versions 4.1.125.Final of netty-codec and 4.2.5.Final of netty-codec-compression.
CWE-409 Improper Handling of Highly Compressed Data (Data Amplification)

CVSSv4:
  • Base Score: MEDIUM (6.9)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-50560  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty HTTP/2 max header size handling produces an attack similar to HTTP/2 Rapid Reset. There is a setting in the http2 specification called `SETTINGS_MAX_HEADER_LIST_SIZE`. When a client sends that setting to Netty, it appears that Netty will behave as follows: read the request; proxy the request to the origin; attempt to produce a response; and create an exception while writing the headers for the response. Functionally, this should be similar to the http2 reset attack, but with a different on-the-wire signature. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv4:
  • Base Score: MEDIUM (6.9)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: MEDIUM (5.3)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-45673  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DNS resolver uses a predictable PRNG for generating DNS transaction IDs and defaults to a static UDP source port. This combination reduces the entropy of DNS queries, enabling DNS Cache Poisoning (Kaminsky attack). Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-340 Generation of Predictable Numbers or Identifiers, CWE-330 Use of Insufficiently Random Values

CVSSv3:
  • Base Score: MEDIUM (6.8)
  • Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N/E:2.2/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2023-34462  

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `SniHandler` can allocate up to 16MB of heap for each channel during the TLS handshake. When the handler or the channel does not have an idle timeout, it can be used to make a TCP server using the `SniHandler` to allocate 16MB of heap. The `SniHandler` class is a handler that waits for the TLS handshake to configure a `SslHandler` according to the indicated server name by the `ClientHello` record. For this matter it allocates a `ByteBuf` using the value defined in the `ClientHello` record. Normally the value of the packet should be smaller than the handshake packet but there are not checks done here and the way the code is written, it is possible to craft a packet that makes the `SslClientHelloHandler`. This vulnerability has been fixed in version 4.1.94.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: MEDIUM (6.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:2.8/RC:R/MAV:A

References:

Vulnerable Software & Versions:

CVE-2025-67735  

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')

CVSSv3:
  • Base Score: MEDIUM (6.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42580  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-190 Integer Overflow or Wraparound

CVSSv3:
  • Base Score: MEDIUM (6.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-56746  

Netty is a network application framework for development of protocol servers and clients. Versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, are vulnerable to security control bypass during the origin evaluation process. CorsHandler provides a shortCircuit() configuration designed to reject unauthorized cross-origin requests immediately, acting as a security control before requests reach the application. However, due to a logical operator error in the origin evaluation process, this protection can be entirely bypassed. An attacker can bypass the short-circuit mechanism by sending a request with an Origin: null header. This failure forwards unauthorized requests to the backend application, bypassing intended access controls. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-284 Improper Access Control

CVSSv3:
  • Base Score: MEDIUM (6.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N/E:2.8/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-59898 (OSSINDEX)  

Netty is an asynchronous, event-driven network application framework.  Prior to versions 4.1.136.Final and 4.2.16.Final, ab attacker can force WebSocket upgrade via the lax V07 (or V08) handshaker by sending `Sec-WebSocket-Version: 7` and omitting `Connection: Upgrade` / `Upgrade: websocket` headers, completing a protocol switch that a proxy would not recognize as an Upgrade request and enabling HTTP request smuggling / protocol-confusion attacks. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

CVSSv2:
  • Base Score: MEDIUM (6.300000190734863)
  • Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

References:

Vulnerable Software & Versions (OSSINDEX):

  • cpe:2.3:a:io.netty:netty-codec-http:4.1.72.Final:*:*:*:*:*:*:*

CVE-2026-59921 (OSSINDEX)  

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, HttpPostRequestEncoder constructs multipart HTTP request bodies by directly concatenating user-supplied filenames and field names into Content-Disposition MIME headers without validating or sanitizing CRLF characters (\r\n). Since MIME headers are delimited by CRLF, an attacker who controls the filename can inject arbitrary MIME headers into the multipart body part. The root cause is that neither the encoder nor the FileUpload implementations' setFilename() methods, which only check for null, neutralize CRLF characters before the filename is embedded into the header. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')

CVSSv3:
  • Base Score: MEDIUM (5.699999809265137)
  • Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

References:

Vulnerable Software & Versions (OSSINDEX):

  • cpe:2.3:a:io.netty:netty-codec-http:4.1.72.Final:*:*:*:*:*:*:*

CVE-2022-24823  

Netty is an open-source, asynchronous event-driven network application framework. The package `io.netty:netty-codec-http` prior to version 4.1.77.Final contains an insufficient fix for CVE-2021-21290. When Netty's multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled. This only impacts applications running on Java version 6 and lower. Additionally, this vulnerability impacts code running on Unix-like systems, and very old versions of Mac OSX and Windows as they all share the system temporary directory between all users. Version 4.1.77.Final contains a patch for this vulnerability. As a workaround, specify one's own `java.io.tmpdir` when starting the JVM or use DefaultHttpDataFactory.setBaseDir(...) to set the directory to something that is only readable by the current user.
CWE-378 Creation of Temporary File With Insecure Permissions, CWE-379 Creation of Temporary File in Directory with Insecure Permissions, CWE-668 Exposure of Resource to Wrong Sphere

CVSSv3:
  • Base Score: MEDIUM (5.5)
  • Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:1.8/RC:R/MAV:A
CVSSv2:
  • Base Score: LOW (1.9)
  • Vector: /AV:L/AC:M/Au:N/C:P/I:N/A:N

References:

Vulnerable Software & Versions: (show all)

CVE-2024-47535  

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. An unsafe reading of environment file could potentially cause a denial of service in Netty. When loaded on an Windows application, Netty attempts to load a file that does not exist. If an attacker creates such a large file, the Netty application crashes. This vulnerability is fixed in 4.1.115.
CWE-400 Uncontrolled Resource Consumption

CVSSv3:
  • Base Score: MEDIUM (5.5)
  • Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:1.8/RC:R/MAV:A

References:

Vulnerable Software & Versions:

CVE-2025-25193  

Netty, an asynchronous, event-driven network application framework, has a vulnerability in versions up to and including 4.1.118.Final. An unsafe reading of environment file could potentially cause a denial of service in Netty. When loaded on an Windows application, Netty attempts to load a file that does not exist. If an attacker creates such a large file, the Netty application crash. A similar issue was previously reported as CVE-2024-47535. This issue was fixed, but the fix was incomplete in that null-bytes were not counted against the input limit. Commit d1fbda62d3a47835d3fb35db8bd42ecc205a5386 contains an updated fix.
CWE-400 Uncontrolled Resource Consumption

CVSSv3:
  • Base Score: MEDIUM (5.5)
  • Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:1.8/RC:R/MAV:A

References:

Vulnerable Software & Versions:

CVE-2024-29025  

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `HttpPostRequestDecoder` can be tricked to accumulate data. While the decoder can store items on the disk if configured so, there are no limits to the number of fields the form can have, an attacher can send a chunked post consisting of many small fields that will be accumulated in the `bodyListHttpData` list. The decoder cumulates bytes in the `undecodedChunk` buffer until it can decode a field, this field can cumulate data without limits. This vulnerability is fixed in 4.1.108.Final.
CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: MEDIUM (5.3)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions:

CVE-2026-41417  

Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')

CVSSv3:
  • Base Score: MEDIUM (5.3)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-47244  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, DefaultHttp2Connection.DefaultEndpoint initialises maxActiveStreams/maxStreams to Integer.MAX_VALUE, and Http2Settings never inserts SETTINGS_MAX_CONCURRENT_STREAMS by default (Http2Settings.java:305-307 only clamps a user-supplied value). Unless the application explicitly calls initialSettings().maxConcurrentStreams(n), a Netty HTTP/2 server advertises no limit and enforces none locally. Each open stream allocates a DefaultStream object, PropertyMap slots, flow-controller state and IntObjectHashMap entry; with ~2^30 permissible odd stream IDs a single TCP connection can create hundreds of thousands of long-lived stream objects. This is also the precondition for CVE-2023-44487-style Rapid-Reset amplification, where the absence of a low concurrent cap multiplies backend work. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-400 Uncontrolled Resource Consumption

CVSSv3:
  • Base Score: MEDIUM (5.3)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-50020  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, before reading the first request-line, `HttpObjectDecoder` skips every byte for which `Character.isISOControl(b)` is `true` (0x00–0x1F and 0x7F) as well as all whitespace. RFC 9112 §2.2 only asks servers to ignore empty CRLF lines preceding the request-line — a carefully scoped robustness allowance intended to handle HTTP/1.0 POST workarounds. Silently absorbing NUL bytes, SOH, STX, and other non-CRLF control characters goes significantly beyond this, and can be exploited for request-boundary confusion in pipelined or multiplexed transports where a front-end component treats those bytes differently. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

CVSSv3:
  • Base Score: MEDIUM (5.3)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-45536  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, netty_unix_socket_recvFd sets msg_control to `char control[CMSG_SPACE(sizeof(int))]` (line 940) — 24 bytes on 64-bit Linux. A peer-sent SCM_RIGHTS cmsg carrying two ints has cmsg_len = CMSG_LEN(8) = 24, which fits exactly with no MSG_CTRUNC, so the kernel installs both fds in the receiving process. The subsequent check `cmsg->cmsg_len == CMSG_LEN(sizeof(int))` (line 972, expected 20) fails, the branch that would read the fd is skipped, and neither installed fd is closed. The for(;;) loop calls recvmsg again (non-blocking → EAGAIN → Java maps to 0 → read loop exits normally), leaving two leaked fds per message. There is no MSG_CTRUNC handling. Reachable via Epoll/KQueue DomainSocketChannel when the application opts into DomainSocketReadMode.FILE_DESCRIPTORS (non-default). Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor, CWE-772 Missing Release of Resource after Effective Lifetime

CVSSv3:
  • Base Score: MEDIUM (4.0)
  • Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:2.5/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2025-58056  

Netty is an asynchronous event-driven network application framework for development of maintainable high performance protocol servers and clients. In versions 4.1.124.Final, and 4.2.0.Alpha3 through 4.2.4.Final, Netty incorrectly accepts standalone newline characters (LF) as a chunk-size line terminator, regardless of a preceding carriage return (CR), instead of requiring CRLF per HTTP/1.1 standards. When combined with reverse proxies that parse LF differently (treating it as part of the chunk extension), attackers can craft requests that the proxy sees as one request but Netty processes as two, enabling request smuggling attacks. This is fixed in versions 4.1.125.Final and 4.2.5.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

CVSSv4:
  • Base Score: LOW (2.9)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42578  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection'), CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')

CVSSv4:
  • Base Score: LOW (2.9)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

netty-codec-protobuf-4.2.7.Final.jar

Description:

Netty is an asynchronous event-driven network application framework for    rapid development of maintainable high performance protocol servers and    clients.

License:

https://www.apache.org/licenses/LICENSE-2.0
File Path: /home/grprdist/.m2/repository/io/netty/netty-codec-protobuf/4.2.7.Final/netty-codec-protobuf-4.2.7.Final.jar
MD5: 8b1621b16afd1dbe5c10c1140e1c3796
SHA1: 228896874d933b1111cdf495c6a57e1207956a99
SHA256:4b25259b6f75ebfc77f014a08f69bad019116d4f5ca548fdc41f3dad8c0de331
Referenced In Project/Scope: Grouper UI:compile
netty-codec-protobuf-4.2.7.Final.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

CVE-2026-45674  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS responses. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-345 Insufficient Verification of Data Authenticity, CWE-346 Origin Validation Error

CVSSv3:
  • Base Score: CRITICAL (10.0)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-47691  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's `DnsResolveContext` insufficiently validates the bailiwick of NS records, enabling DNS Cache Poisoning. An attacker controlling an authoritative name server for a subdomain can poison the cache for parent domains (like `.co.uk`). In `io.netty.resolver.dns.DnsResolveContext.AuthoritativeNameServerList#add` method accepts any NS record from the AUTHORITY section as long as the record's name is a suffix of the questionName. Subsequently, the `handleWithAdditional` method caches the associated A records from the ADDITIONAL section directly into the `authoritativeDnsServerCache` under the parent domain's key. This bypasses standard bailiwick rules, where a server authoritative for a subdomain should not be trusted to provide authoritative records for its parent. The poisoned cache is then used for all future resolutions under the parent domain's key. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-345 Insufficient Verification of Data Authenticity, CWE-346 Origin Validation Error

CVSSv3:
  • Base Score: CRITICAL (10.0)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42581  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

CVSSv3:
  • Base Score: CRITICAL (9.8)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42579  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-20 Improper Input Validation, CWE-626 Null Byte Interaction Error (Poison Null Byte), CWE-1286 Improper Validation of Syntactic Correctness of Input

CVSSv3:
  • Base Score: CRITICAL (9.1)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42584  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

CVSSv3:
  • Base Score: CRITICAL (9.1)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-56820  

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final, `OcspClient` does not validate that the `CertificateID` in an OCSP response matches the requested `CertificateID`, which can lead to replay attack. `OcspClient.validateResponse` accepts a legitimately signed `GOOD` status response for an unrelated certificate issued by the same CA, allowing bypass of revocation checks for another certificate. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-295 Improper Certificate Validation

CVSSv3:
  • Base Score: CRITICAL (9.1)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-33871  

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv4:
  • Base Score: HIGH (8.7)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-48006  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the RedisArrayAggregator handler permanently leaks pooled direct-memory buffers when a Redis pipeline connection closes before a RESP array aggregate completes. The handler retains child messages in per-handler state (`depths` field) but defines no `channelInactive`, `handlerRemoved`, or `exceptionCaught` method to release them when the pipeline tears down. Because the leaked buffers are slices of `PooledByteBufAllocator` chunks, they prevent those chunks from being returned to the JVM-wide direct-memory pool. Repeated connection churn by any network peer monotonically drains this shared pool, eventually causing allocation failures on all Netty channels in the process. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-401 Missing Release of Memory after Effective Lifetime, CWE-772 Missing Release of Resource after Effective Lifetime

CVSSv4:
  • Base Score: HIGH (8.7)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-48059  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the HAProxy PROXY protocol v2 codec in netty leaks native or heap memory on every connection when a client sends a syntactically valid header containing nested `PP2_TYPE_SSL` TLVs (type-length-value records) at depth two or greater. The leak occurs on the successful parse path — no exception is thrown, the message fires downstream, the decoder removes itself, and the application releases the `HAProxyMessage` normally. Yet the underlying cumulation buffer (a pooled, potentially direct `ByteBuf` allocated by the channel) remains permanently pinned. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-401 Missing Release of Memory after Effective Lifetime, CWE-1286 Improper Validation of Syntactic Correctness of Input

CVSSv4:
  • Base Score: HIGH (8.7)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-55851  

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final up to (but not including) 4.2.16.Final, and 4.1.0.Final up to (but not including) 4.1.135, the `HAProxyMessageDecoder` in Netty's `codec-haproxy` module performs protocol version detection by reading the 13th byte as a signed Java `byte` and widening it to `int` without masking; a PROXY protocol v2 binary prefix followed by version byte `0xFF` sign-extends to `-1`, collides with the decoder's need-more-data sentinel, and causes `ByteToMessageDecoder` to accumulate inbound bytes in an unbounded `cumulation` buffer until direct memory is exhausted. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-400 Uncontrolled Resource Consumption

CVSSv4:
  • Base Score: HIGH (8.7)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-56745  

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, the `SpdyHttpDecoder` handler in Netty's SPDY-to-HTTP codec allocates a pooled `ByteBuf` when processing a client-initiated `SYN_STREAM` frame with `FLAG_FIN=0` and stores the partially constructed `FullHttpRequest` in `messageMap`; when the remote peer sends `RST_STREAM` for that stream or the accumulated content exceeds `maxContentLength`, the decoder removes the entry but does not release the pooled `ByteBuf`, causing native memory exhaustion. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-400 Uncontrolled Resource Consumption

CVSSv4:
  • Base Score: HIGH (8.7)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-56817  

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, any caller that can deliver bytes to a Netty channel pipeline containing `XmlDecoder` can send XML with a `DOCTYPE` declaration to an `AsyncXMLInputFactory` instantiated with no security configuration, leaving DTD and entity handling active depending on Aalto XML async parser behavior and creating conditional XML external entity risk. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-611 Improper Restriction of XML External Entity Reference

CVSSv4:
  • Base Score: HIGH (8.3)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: CRITICAL (9.8)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-44249  

Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-697 Incorrect Comparison, CWE-1287 Improper Validation of Specified Type of Input, CWE-284 Improper Access Control

CVSSv3:
  • Base Score: HIGH (8.1)
  • Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:2.2/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-33870  

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42577  

Netty is an asynchronous, event-driven network application framework. From 4.2.0.Final to 4.2.13.Final , Netty's epoll transport fails to detect and close TCP connections that receive a RST after being half-closed, leading to stale channels that are never cleaned up and, in some code paths, a 100% CPU busy-loop in the event loop thread. This vulnerability is fixed in 4.2.13.Final.
CWE-772 Missing Release of Resource after Effective Lifetime

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions:

CVE-2026-42582  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length bytes are actually present in the compressed field section. The wire encoding allows a very large length to be expressed in few bytes. There is no check that length <= in.readableBytes() before new byte[length]. This vulnerability is fixed in 4.2.13.Final.
CWE-789 Memory Allocation with Excessive Size Value, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions:

CVE-2026-42583  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42585  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42587  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-44248  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion. This can cause high resource usage in both CPU and memory. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-44250  

Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can cause DoS by sending a crafted Redis payload with deeply nested arrays. This forces the server to allocate a massive number of state objects and collections, leading to memory exhaustion and an OutOfMemoryError. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-44890  

Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can cause DoS by sending crafted Redis payloads across multiple connections without `\r\n`. This exhausts the server's direct memory pool (OutOfDirectMemoryError), preventing legitimate connections from being processed. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-44891  

Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.stomp.StompSubframeDecoder fails to limit the total number of headers or their cumulative size per frame, and the maxLineLength parameter only restricts individual header lines. An attacker can send a large number of short headers that are accumulated in memory inside DefaultStompHeadersSubframe until the JVM throws an OutOfMemoryError, causing denial of service for servers exposing a STOMP endpoint based on StompSubframeDecoder. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-44892  

Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final, the default configuration of the `Http3ConnectionHandler` in the Netty HTTP/3 codec lacks an enforced maximum header size limit. When a peer does not explicitly specify `HTTP3_SETTINGS_MAX_FIELD_SECTION_SIZE`, the implementation defaults to an unbounded limit. This insecure default configuration allows a malicious client or server to send an enormous number of headers, leading to a memory exhaustion Denial of Service via an `OutOfMemoryError`. Version 4.2.15.Final contains a patch.
CWE-400 Uncontrolled Resource Consumption, CWE-1188 Insecure Default Initialization of Resource

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions:

CVE-2026-44893  

Netty is a network application framework for development of protocol servers and clients. In netty-codec-haproxy prior to versions 4.1.135.Final and 4.2.15.Final, when decoding a PP2_TYPE_SSL TLV, HAProxyMessage.readNextTLV() first calls `header.retainedSlice(header.readerIndex(), length)` and only then reads the 1-byte client field and 4-byte verify field. If the attacker sets the TLV length below 5, the subsequent readByte/readInt throws IndexOutOfBoundsException. HAProxyMessageDecoder only catches HAProxyProtocolException around this call, so the IOOBE propagates and the retained slice on the pooled cumulation buffer is never released. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-703 Improper Check or Handling of Exceptional Conditions, CWE-805 Buffer Access with Incorrect Length Value

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-44894  

Netty is a network application framework for development of protocol servers and clients. NoQuicTokenHandler is the tokenHandler used when the application does not set one. Prior to version 4.2.15.Final, its writeToken() returns false (server will not send Retry — acceptable), but validateToken() unconditionally `return 0`. In QuicheQuicServerCodec.handlePacket(), a non-negative return from validateToken() is interpreted as 'token is valid, ODCID starts at offset 0', causing the server to call quiche_accept as if the client's address had been validated by a Retry round-trip. Per RFC 9000 §8.1, a validated address lifts the 3× anti-amplification send limit. Thus any attacker who includes ANY non-empty token bytes in an Initial packet — with a spoofed victim source IP — causes the Netty server to treat the victim as validated and reflect full-size handshake flights (certificates, etc.) toward it without the 3× cap. The correct 'no token handler' semantics would be to return -1 (invalid) so the normal un-validated path and amplification limit apply. Version 4.2.15.Final patches the issue.
CWE-940 Improper Verification of Source of a Communication Channel, CWE-346 Origin Validation Error

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions:

CVE-2026-45416  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SslClientHelloHandler.decode() reads the 24-bit TLS handshake length and, when the ClientHello does not fit in the first record, eagerly allocates `ctx.alloc().buffer(handshakeLength)` (line 161). The guard at line 140 is `handshakeLength > maxClientHelloLength && maxClientHelloLength != 0`, and the commonly-used SniHandler/AbstractSniHandler constructors (SniHandler(Mapping), SniHandler(AsyncMapping), AbstractSniHandler()) pass maxClientHelloLength=0 and handshakeTimeoutMillis=0, so the length guard is disabled and no timeout is scheduled. A 16 MiB request exceeds the default pooled chunk size and becomes a huge/unpooled allocation performed immediately. The buffer is retained in the handler until the channel closes. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-46340  

Netty is a network application framework for development of protocol servers and clients. In versions of netty-transport-sctp prior to 4.1.135.Final and 4.2.15.Final, for each non-complete SctpMessage fragment the handler does `fragments.put(streamId, Unpooled.wrappedBuffer(frag, byteBuf))`, wrapping the previous accumulator and the new slice into a *new* CompositeByteBuf every time. After N fragments the accumulator is an N-deep chain of composites, each holding references and component arrays; readableBytes()/getBytes() on the final buffer recurse N levels. There is no limit on N, on total bytes, or on the number of streamIdentifiers an attacker can open (each gets its own map entry). A peer that never sets the `complete` flag can grow this structure indefinitely from tiny 1-byte DATA chunks. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-48043  

Netty is a network application framework for development of protocol servers and clients. In netty-codec-http2 prior to versions 4.1.135.Final and 4.2.15.Final, the `DelegatingDecompressorFrameListener` class orchestrates HTTP/2 decompression by embedding a per-stream `EmbeddedChannel` that runs the appropriate decompression codec (gzip, deflate, zstd) and forwards decompressed chunks to a wrapped listener. Each decompressed chunk is a pooled `ByteBuf` handed to an anonymous `ChannelInboundHandlerAdapter` tail handler, which becomes the sole owner responsible for releasing it. A remote peer could send frames that would result in the flow-controller throwing and so trigger a resource leak which at the end might take down the whole JVM due OOME. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-400 Uncontrolled Resource Consumption, CWE-401 Missing Release of Memory after Effective Lifetime, CWE-772 Missing Release of Resource after Effective Lifetime

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-48748  

Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final, a memory exhaustion vulnerability in the Netty HTTP/3 codec allows the creation of an infinite number of blocked streams, which can cause OOM error. Version 4.2.15.Final patches the issue.
CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions:

CVE-2026-50010  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SimpleTrustManagerFactory.engineGetTrustManagers() and related paths wrap any user-supplied plain X509TrustManager in X509TrustManagerWrapper, which extends X509ExtendedTrustManager but implements the 3-arg checkServerTrusted(chain, authType, SSLEngine) by discarding the SSLEngine and calling the 2-arg delegate. Because the object now IS an X509ExtendedTrustManager, neither SunJSSE's internal AbstractTrustManagerWrapper nor Netty's own OpenSslX509TrustManagerWrapper will re-wrap it to add endpoint-identification. Consequently, even though Netty 4.2 sets endpointIdentificationAlgorithm="HTTPS" by default, a client built with `SslContextBuilder.forClient().trustManager(somePlainX509TrustManager)` performs no hostname verification at all. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-347 Improper Verification of Cryptographic Signature

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-50011  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, RedisArrayAggregator pre-allocates ArrayList with initial capacity equal to the RESP array element count declared in an array header. That count is taken from the wire before the corresponding child messages exist. A small malicious header can claim a huge initial capacity. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-55831  

Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length limit and materializes every unique setting ID in `DefaultSpdySettingsFrame`, allowing a remote SPDY/3.1 peer to send a syntactically valid roughly 2 MiB SETTINGS frame that creates 262144 map entries and amplifies network input into heap growth and ordered-map insertion work. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-55833  

Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has exceeded `maxHeaderSize` and marked the frame truncated in `SpdyFrameCodec`, allowing a remote peer to send a small compressed `HEADERS` block that expands into much larger raw header data and causes compression-amplified CPU and allocation churn. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-400 Uncontrolled Resource Consumption

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-56816  

Netty is a network application framework for development of protocol servers and clients. Prior to 4.2.16.Final, Netty's `Http3FrameCodec` buffers incoming data for HTTP/3 reserved frame types up to the wire-specified payload length without limits; `decodeFrame` trusts `payLoadLength`, allowing an attacker to open multiple QUIC streams and send reserved frames with very large payload lengths to cause memory exhaustion and denial of service. This issue is fixed in version 4.2.16.Final.
CWE-400 Uncontrolled Resource Consumption

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions:

CVE-2026-56819  

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, a remote unauthenticated peer can leak one direct `ByteBuf` per HTTP/2 `DATA` frame in applications that enable HTTP/2 content decompression via `DelegatingDecompressorFrameListener`. When a `DATA` frame is processed for a stream whose decompressor has already been closed, `Http2Decompressor.decompress(...)` calls `decompressor.writeInbound(data.retain())` and does not release the retained buffer on the error path, eventually exhausting direct memory and crashing the JVM. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-401 Missing Release of Memory after Effective Lifetime

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42586  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')

CVSSv3:
  • Base Score: HIGH (7.1)
  • Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:1.8/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-50560  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty HTTP/2 max header size handling produces an attack similar to HTTP/2 Rapid Reset. There is a setting in the http2 specification called `SETTINGS_MAX_HEADER_LIST_SIZE`. When a client sends that setting to Netty, it appears that Netty will behave as follows: read the request; proxy the request to the origin; attempt to produce a response; and create an exception while writing the headers for the response. Functionally, this should be similar to the http2 reset attack, but with a different on-the-wire signature. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv4:
  • Base Score: MEDIUM (6.9)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: MEDIUM (5.3)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-45673  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DNS resolver uses a predictable PRNG for generating DNS transaction IDs and defaults to a static UDP source port. This combination reduces the entropy of DNS queries, enabling DNS Cache Poisoning (Kaminsky attack). Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-340 Generation of Predictable Numbers or Identifiers, CWE-330 Use of Insufficiently Random Values

CVSSv3:
  • Base Score: MEDIUM (6.8)
  • Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N/E:2.2/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2025-67735  

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')

CVSSv3:
  • Base Score: MEDIUM (6.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42580  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-190 Integer Overflow or Wraparound

CVSSv3:
  • Base Score: MEDIUM (6.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-56746  

Netty is a network application framework for development of protocol servers and clients. Versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, are vulnerable to security control bypass during the origin evaluation process. CorsHandler provides a shortCircuit() configuration designed to reject unauthorized cross-origin requests immediately, acting as a security control before requests reach the application. However, due to a logical operator error in the origin evaluation process, this protection can be entirely bypassed. An attacker can bypass the short-circuit mechanism by sending a request with an Origin: null header. This failure forwards unauthorized requests to the backend application, bypassing intended access controls. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-284 Improper Access Control

CVSSv3:
  • Base Score: MEDIUM (6.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N/E:2.8/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-41417  

Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')

CVSSv3:
  • Base Score: MEDIUM (5.3)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-47244  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, DefaultHttp2Connection.DefaultEndpoint initialises maxActiveStreams/maxStreams to Integer.MAX_VALUE, and Http2Settings never inserts SETTINGS_MAX_CONCURRENT_STREAMS by default (Http2Settings.java:305-307 only clamps a user-supplied value). Unless the application explicitly calls initialSettings().maxConcurrentStreams(n), a Netty HTTP/2 server advertises no limit and enforces none locally. Each open stream allocates a DefaultStream object, PropertyMap slots, flow-controller state and IntObjectHashMap entry; with ~2^30 permissible odd stream IDs a single TCP connection can create hundreds of thousands of long-lived stream objects. This is also the precondition for CVE-2023-44487-style Rapid-Reset amplification, where the absence of a low concurrent cap multiplies backend work. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-400 Uncontrolled Resource Consumption

CVSSv3:
  • Base Score: MEDIUM (5.3)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-50020  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, before reading the first request-line, `HttpObjectDecoder` skips every byte for which `Character.isISOControl(b)` is `true` (0x00–0x1F and 0x7F) as well as all whitespace. RFC 9112 §2.2 only asks servers to ignore empty CRLF lines preceding the request-line — a carefully scoped robustness allowance intended to handle HTTP/1.0 POST workarounds. Silently absorbing NUL bytes, SOH, STX, and other non-CRLF control characters goes significantly beyond this, and can be exploited for request-boundary confusion in pipelined or multiplexed transports where a front-end component treats those bytes differently. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

CVSSv3:
  • Base Score: MEDIUM (5.3)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-50009  

Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final, Netty QUIC exposes the stateless reset token on the network path when using the default HMAC-based connection-ID and stateless-reset-token generators. The reset token for the server's current source connection ID can be derived from bytes that appear as the connection ID in QUIC headers after a source-CID rotation. An on-path attacker observing the headers can use the token to perform a Denial of Service by sending a spoofed Stateless Reset packet. Version 4.2.15.Final patches the issue.
CWE-330 Use of Insufficiently Random Values, CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

CVSSv3:
  • Base Score: MEDIUM (4.8)
  • Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L/E:2.2/RC:R/MAV:A

References:

Vulnerable Software & Versions:

CVE-2026-45536  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, netty_unix_socket_recvFd sets msg_control to `char control[CMSG_SPACE(sizeof(int))]` (line 940) — 24 bytes on 64-bit Linux. A peer-sent SCM_RIGHTS cmsg carrying two ints has cmsg_len = CMSG_LEN(8) = 24, which fits exactly with no MSG_CTRUNC, so the kernel installs both fds in the receiving process. The subsequent check `cmsg->cmsg_len == CMSG_LEN(sizeof(int))` (line 972, expected 20) fails, the branch that would read the fd is skipped, and neither installed fd is closed. The for(;;) loop calls recvmsg again (non-blocking → EAGAIN → Java maps to 0 → read loop exits normally), leaving two leaked fds per message. There is no MSG_CTRUNC handling. Reachable via Epoll/KQueue DomainSocketChannel when the application opts into DomainSocketReadMode.FILE_DESCRIPTORS (non-default). Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor, CWE-772 Missing Release of Resource after Effective Lifetime

CVSSv3:
  • Base Score: MEDIUM (4.0)
  • Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:2.5/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42578  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection'), CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')

CVSSv4:
  • Base Score: LOW (2.9)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

netty-common-4.1.72.Final.jar (shaded: org.jctools:jctools-core:3.1.0)

Description:

Java Concurrency Tools Core Library

License:

Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/io/netty/netty-common/4.1.72.Final/netty-common-4.1.72.Final.jar/META-INF/maven/org.jctools/jctools-core/pom.xml
MD5: 08e7326c64d7fd6ae4ea32e7eb4e5b79
SHA1: 9deceaba814dea198202b04fe0eec0d2dbf69ea9
SHA256:acaf1b4c366f6794a734288a2c003f16af90a9c479cf4d7daade689764e4fb47
Referenced In Project/Scope: Grouper UI:compile

Identifiers

netty-transport-4.1.72.Final.jar

Description:

Netty is an asynchronous event-driven network application framework for    rapid development of maintainable high performance protocol servers and    clients.

License:

https://www.apache.org/licenses/LICENSE-2.0
File Path: /home/grprdist/.m2/repository/io/netty/netty-transport/4.1.72.Final/netty-transport-4.1.72.Final.jar
MD5: 6f4128413f9200c948bcceb2299bb7e5
SHA1: 99138b436a584879355aca8fe3c64b46227d5d79
SHA256:c5fb68e9a65b6e8a516adfcb9fa323479ee7b4d9449d8a529d2ecab3d3711d5a
Referenced In Project/Scope: Grouper UI:compile
netty-transport-4.1.72.Final.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

CVE-2026-45674  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS responses. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-345 Insufficient Verification of Data Authenticity, CWE-346 Origin Validation Error

CVSSv3:
  • Base Score: CRITICAL (10.0)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-47691  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's `DnsResolveContext` insufficiently validates the bailiwick of NS records, enabling DNS Cache Poisoning. An attacker controlling an authoritative name server for a subdomain can poison the cache for parent domains (like `.co.uk`). In `io.netty.resolver.dns.DnsResolveContext.AuthoritativeNameServerList#add` method accepts any NS record from the AUTHORITY section as long as the record's name is a suffix of the questionName. Subsequently, the `handleWithAdditional` method caches the associated A records from the ADDITIONAL section directly into the `authoritativeDnsServerCache` under the parent domain's key. This bypasses standard bailiwick rules, where a server authoritative for a subdomain should not be trusted to provide authoritative records for its parent. The poisoned cache is then used for all future resolutions under the parent domain's key. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-345 Insufficient Verification of Data Authenticity, CWE-346 Origin Validation Error

CVSSv3:
  • Base Score: CRITICAL (10.0)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42581  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

CVSSv3:
  • Base Score: CRITICAL (9.8)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42579  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-20 Improper Input Validation, CWE-626 Null Byte Interaction Error (Poison Null Byte), CWE-1286 Improper Validation of Syntactic Correctness of Input

CVSSv3:
  • Base Score: CRITICAL (9.1)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42584  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

CVSSv3:
  • Base Score: CRITICAL (9.1)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-56820  

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final, `OcspClient` does not validate that the `CertificateID` in an OCSP response matches the requested `CertificateID`, which can lead to replay attack. `OcspClient.validateResponse` accepts a legitimately signed `GOOD` status response for an unrelated certificate issued by the same CA, allowing bypass of revocation checks for another certificate. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-295 Improper Certificate Validation

CVSSv3:
  • Base Score: CRITICAL (9.1)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-33871  

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv4:
  • Base Score: HIGH (8.7)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-48006  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the RedisArrayAggregator handler permanently leaks pooled direct-memory buffers when a Redis pipeline connection closes before a RESP array aggregate completes. The handler retains child messages in per-handler state (`depths` field) but defines no `channelInactive`, `handlerRemoved`, or `exceptionCaught` method to release them when the pipeline tears down. Because the leaked buffers are slices of `PooledByteBufAllocator` chunks, they prevent those chunks from being returned to the JVM-wide direct-memory pool. Repeated connection churn by any network peer monotonically drains this shared pool, eventually causing allocation failures on all Netty channels in the process. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-401 Missing Release of Memory after Effective Lifetime, CWE-772 Missing Release of Resource after Effective Lifetime

CVSSv4:
  • Base Score: HIGH (8.7)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-48059  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the HAProxy PROXY protocol v2 codec in netty leaks native or heap memory on every connection when a client sends a syntactically valid header containing nested `PP2_TYPE_SSL` TLVs (type-length-value records) at depth two or greater. The leak occurs on the successful parse path — no exception is thrown, the message fires downstream, the decoder removes itself, and the application releases the `HAProxyMessage` normally. Yet the underlying cumulation buffer (a pooled, potentially direct `ByteBuf` allocated by the channel) remains permanently pinned. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-401 Missing Release of Memory after Effective Lifetime, CWE-1286 Improper Validation of Syntactic Correctness of Input

CVSSv4:
  • Base Score: HIGH (8.7)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-55851  

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final up to (but not including) 4.2.16.Final, and 4.1.0.Final up to (but not including) 4.1.135, the `HAProxyMessageDecoder` in Netty's `codec-haproxy` module performs protocol version detection by reading the 13th byte as a signed Java `byte` and widening it to `int` without masking; a PROXY protocol v2 binary prefix followed by version byte `0xFF` sign-extends to `-1`, collides with the decoder's need-more-data sentinel, and causes `ByteToMessageDecoder` to accumulate inbound bytes in an unbounded `cumulation` buffer until direct memory is exhausted. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-400 Uncontrolled Resource Consumption

CVSSv4:
  • Base Score: HIGH (8.7)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-56745  

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, the `SpdyHttpDecoder` handler in Netty's SPDY-to-HTTP codec allocates a pooled `ByteBuf` when processing a client-initiated `SYN_STREAM` frame with `FLAG_FIN=0` and stores the partially constructed `FullHttpRequest` in `messageMap`; when the remote peer sends `RST_STREAM` for that stream or the accumulated content exceeds `maxContentLength`, the decoder removes the entry but does not release the pooled `ByteBuf`, causing native memory exhaustion. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-400 Uncontrolled Resource Consumption

CVSSv4:
  • Base Score: HIGH (8.7)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-56817  

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, any caller that can deliver bytes to a Netty channel pipeline containing `XmlDecoder` can send XML with a `DOCTYPE` declaration to an `AsyncXMLInputFactory` instantiated with no security configuration, leaving DTD and entity handling active depending on Aalto XML async parser behavior and creating conditional XML external entity risk. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-611 Improper Restriction of XML External Entity Reference

CVSSv4:
  • Base Score: HIGH (8.3)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: CRITICAL (9.8)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2025-55163  

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.124.Final and 4.2.4.Final, Netty is vulnerable to MadeYouReset DDoS. This is a logical vulnerability in the HTTP/2 protocol, that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit - which results in resource exhaustion and distributed denial of service. This issue has been patched in versions 4.1.124.Final and 4.2.4.Final.
CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv4:
  • Base Score: HIGH (8.2)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-44249  

Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-697 Incorrect Comparison, CWE-1287 Improper Validation of Specified Type of Input, CWE-284 Improper Access Control

CVSSv3:
  • Base Score: HIGH (8.1)
  • Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:2.2/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2022-41881  

Netty project is an event-driven asynchronous network application framework. In versions prior to 4.1.86.Final, a StackOverflowError can be raised when parsing a malformed crafted message due to an infinite recursion. This issue is patched in version 4.1.86.Final. There is no workaround, except using a custom HaProxyMessageDecoder.
CWE-674 Uncontrolled Recursion

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions:

CVE-2023-44487  

CISA Known Exploited Vulnerability:
  • Product: IETF HTTP/2
  • Name: HTTP/2 Rapid Reset Attack Vulnerability
  • Date Added: 2023-10-10
  • Description: HTTP/2 contains a rapid reset vulnerability that allows for a distributed denial-of-service attack (DDoS).
  • Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
  • Due Date: 2023-10-31
  • Notes: This vulnerability affects a common open-source component, third-party library, or protocol used by different products. For more information, please see: HTTP/2 Rapid Reset Vulnerability, CVE-2023-44487 | CISA: https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487; https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/; https://nvd.nist.gov/vuln/detail/CVE-2023-44487

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CWE-400 Uncontrolled Resource Consumption, NVD-CWE-noinfo

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-33870  

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42583  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42585  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42587  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-44248  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion. This can cause high resource usage in both CPU and memory. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-44250  

Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can cause DoS by sending a crafted Redis payload with deeply nested arrays. This forces the server to allocate a massive number of state objects and collections, leading to memory exhaustion and an OutOfMemoryError. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-44890  

Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can cause DoS by sending crafted Redis payloads across multiple connections without `\r\n`. This exhausts the server's direct memory pool (OutOfDirectMemoryError), preventing legitimate connections from being processed. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-44891  

Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.stomp.StompSubframeDecoder fails to limit the total number of headers or their cumulative size per frame, and the maxLineLength parameter only restricts individual header lines. An attacker can send a large number of short headers that are accumulated in memory inside DefaultStompHeadersSubframe until the JVM throws an OutOfMemoryError, causing denial of service for servers exposing a STOMP endpoint based on StompSubframeDecoder. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-44893  

Netty is a network application framework for development of protocol servers and clients. In netty-codec-haproxy prior to versions 4.1.135.Final and 4.2.15.Final, when decoding a PP2_TYPE_SSL TLV, HAProxyMessage.readNextTLV() first calls `header.retainedSlice(header.readerIndex(), length)` and only then reads the 1-byte client field and 4-byte verify field. If the attacker sets the TLV length below 5, the subsequent readByte/readInt throws IndexOutOfBoundsException. HAProxyMessageDecoder only catches HAProxyProtocolException around this call, so the IOOBE propagates and the retained slice on the pooled cumulation buffer is never released. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-703 Improper Check or Handling of Exceptional Conditions, CWE-805 Buffer Access with Incorrect Length Value

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-45416  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SslClientHelloHandler.decode() reads the 24-bit TLS handshake length and, when the ClientHello does not fit in the first record, eagerly allocates `ctx.alloc().buffer(handshakeLength)` (line 161). The guard at line 140 is `handshakeLength > maxClientHelloLength && maxClientHelloLength != 0`, and the commonly-used SniHandler/AbstractSniHandler constructors (SniHandler(Mapping), SniHandler(AsyncMapping), AbstractSniHandler()) pass maxClientHelloLength=0 and handshakeTimeoutMillis=0, so the length guard is disabled and no timeout is scheduled. A 16 MiB request exceeds the default pooled chunk size and becomes a huge/unpooled allocation performed immediately. The buffer is retained in the handler until the channel closes. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-46340  

Netty is a network application framework for development of protocol servers and clients. In versions of netty-transport-sctp prior to 4.1.135.Final and 4.2.15.Final, for each non-complete SctpMessage fragment the handler does `fragments.put(streamId, Unpooled.wrappedBuffer(frag, byteBuf))`, wrapping the previous accumulator and the new slice into a *new* CompositeByteBuf every time. After N fragments the accumulator is an N-deep chain of composites, each holding references and component arrays; readableBytes()/getBytes() on the final buffer recurse N levels. There is no limit on N, on total bytes, or on the number of streamIdentifiers an attacker can open (each gets its own map entry). A peer that never sets the `complete` flag can grow this structure indefinitely from tiny 1-byte DATA chunks. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-48043  

Netty is a network application framework for development of protocol servers and clients. In netty-codec-http2 prior to versions 4.1.135.Final and 4.2.15.Final, the `DelegatingDecompressorFrameListener` class orchestrates HTTP/2 decompression by embedding a per-stream `EmbeddedChannel` that runs the appropriate decompression codec (gzip, deflate, zstd) and forwards decompressed chunks to a wrapped listener. Each decompressed chunk is a pooled `ByteBuf` handed to an anonymous `ChannelInboundHandlerAdapter` tail handler, which becomes the sole owner responsible for releasing it. A remote peer could send frames that would result in the flow-controller throwing and so trigger a resource leak which at the end might take down the whole JVM due OOME. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-400 Uncontrolled Resource Consumption, CWE-401 Missing Release of Memory after Effective Lifetime, CWE-772 Missing Release of Resource after Effective Lifetime

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-50010  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SimpleTrustManagerFactory.engineGetTrustManagers() and related paths wrap any user-supplied plain X509TrustManager in X509TrustManagerWrapper, which extends X509ExtendedTrustManager but implements the 3-arg checkServerTrusted(chain, authType, SSLEngine) by discarding the SSLEngine and calling the 2-arg delegate. Because the object now IS an X509ExtendedTrustManager, neither SunJSSE's internal AbstractTrustManagerWrapper nor Netty's own OpenSslX509TrustManagerWrapper will re-wrap it to add endpoint-identification. Consequently, even though Netty 4.2 sets endpointIdentificationAlgorithm="HTTPS" by default, a client built with `SslContextBuilder.forClient().trustManager(somePlainX509TrustManager)` performs no hostname verification at all. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-347 Improper Verification of Cryptographic Signature

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-50011  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, RedisArrayAggregator pre-allocates ArrayList with initial capacity equal to the RESP array element count declared in an array header. That count is taken from the wire before the corresponding child messages exist. A small malicious header can claim a huge initial capacity. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-55831  

Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length limit and materializes every unique setting ID in `DefaultSpdySettingsFrame`, allowing a remote SPDY/3.1 peer to send a syntactically valid roughly 2 MiB SETTINGS frame that creates 262144 map entries and amplifies network input into heap growth and ordered-map insertion work. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-55833  

Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has exceeded `maxHeaderSize` and marked the frame truncated in `SpdyFrameCodec`, allowing a remote peer to send a small compressed `HEADERS` block that expands into much larger raw header data and causes compression-amplified CPU and allocation churn. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-400 Uncontrolled Resource Consumption

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-56816  

Netty is a network application framework for development of protocol servers and clients. Prior to 4.2.16.Final, Netty's `Http3FrameCodec` buffers incoming data for HTTP/3 reserved frame types up to the wire-specified payload length without limits; `decodeFrame` trusts `payLoadLength`, allowing an attacker to open multiple QUIC streams and send reserved frames with very large payload lengths to cause memory exhaustion and denial of service. This issue is fixed in version 4.2.16.Final.
CWE-400 Uncontrolled Resource Consumption

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions:

CVE-2026-56819  

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, a remote unauthenticated peer can leak one direct `ByteBuf` per HTTP/2 `DATA` frame in applications that enable HTTP/2 content decompression via `DelegatingDecompressorFrameListener`. When a `DATA` frame is processed for a stream whose decompressor has already been closed, `Http2Decompressor.decompress(...)` calls `decompressor.writeInbound(data.retain())` and does not release the retained buffer on the error path, eventually exhausting direct memory and crashing the JVM. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-401 Missing Release of Memory after Effective Lifetime

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42586  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')

CVSSv3:
  • Base Score: HIGH (7.1)
  • Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:1.8/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2025-58057  

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In netty-codec-compression versions 4.1.124.Final and below, and netty-codec versions 4.2.4.Final and below, when supplied with specially crafted input, BrotliDecoder and certain other decompression decoders will allocate a large number of reachable byte buffers, which can lead to denial of service. BrotliDecoder.decompress has no limit in how often it calls pull, decompressing data 64K bytes at a time. The buffers are saved in the output list, and remain reachable until OOM is hit. This is fixed in versions 4.1.125.Final of netty-codec and 4.2.5.Final of netty-codec-compression.
CWE-409 Improper Handling of Highly Compressed Data (Data Amplification)

CVSSv4:
  • Base Score: MEDIUM (6.9)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-50560  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty HTTP/2 max header size handling produces an attack similar to HTTP/2 Rapid Reset. There is a setting in the http2 specification called `SETTINGS_MAX_HEADER_LIST_SIZE`. When a client sends that setting to Netty, it appears that Netty will behave as follows: read the request; proxy the request to the origin; attempt to produce a response; and create an exception while writing the headers for the response. Functionally, this should be similar to the http2 reset attack, but with a different on-the-wire signature. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv4:
  • Base Score: MEDIUM (6.9)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: MEDIUM (5.3)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-45673  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DNS resolver uses a predictable PRNG for generating DNS transaction IDs and defaults to a static UDP source port. This combination reduces the entropy of DNS queries, enabling DNS Cache Poisoning (Kaminsky attack). Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-340 Generation of Predictable Numbers or Identifiers, CWE-330 Use of Insufficiently Random Values

CVSSv3:
  • Base Score: MEDIUM (6.8)
  • Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N/E:2.2/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2023-34462  

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `SniHandler` can allocate up to 16MB of heap for each channel during the TLS handshake. When the handler or the channel does not have an idle timeout, it can be used to make a TCP server using the `SniHandler` to allocate 16MB of heap. The `SniHandler` class is a handler that waits for the TLS handshake to configure a `SslHandler` according to the indicated server name by the `ClientHello` record. For this matter it allocates a `ByteBuf` using the value defined in the `ClientHello` record. Normally the value of the packet should be smaller than the handshake packet but there are not checks done here and the way the code is written, it is possible to craft a packet that makes the `SslClientHelloHandler`. This vulnerability has been fixed in version 4.1.94.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: MEDIUM (6.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:2.8/RC:R/MAV:A

References:

Vulnerable Software & Versions:

CVE-2025-67735  

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')

CVSSv3:
  • Base Score: MEDIUM (6.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42580  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-190 Integer Overflow or Wraparound

CVSSv3:
  • Base Score: MEDIUM (6.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-56746  

Netty is a network application framework for development of protocol servers and clients. Versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, are vulnerable to security control bypass during the origin evaluation process. CorsHandler provides a shortCircuit() configuration designed to reject unauthorized cross-origin requests immediately, acting as a security control before requests reach the application. However, due to a logical operator error in the origin evaluation process, this protection can be entirely bypassed. An attacker can bypass the short-circuit mechanism by sending a request with an Origin: null header. This failure forwards unauthorized requests to the backend application, bypassing intended access controls. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-284 Improper Access Control

CVSSv3:
  • Base Score: MEDIUM (6.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N/E:2.8/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2022-24823  

Netty is an open-source, asynchronous event-driven network application framework. The package `io.netty:netty-codec-http` prior to version 4.1.77.Final contains an insufficient fix for CVE-2021-21290. When Netty's multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled. This only impacts applications running on Java version 6 and lower. Additionally, this vulnerability impacts code running on Unix-like systems, and very old versions of Mac OSX and Windows as they all share the system temporary directory between all users. Version 4.1.77.Final contains a patch for this vulnerability. As a workaround, specify one's own `java.io.tmpdir` when starting the JVM or use DefaultHttpDataFactory.setBaseDir(...) to set the directory to something that is only readable by the current user.
CWE-378 Creation of Temporary File With Insecure Permissions, CWE-379 Creation of Temporary File in Directory with Insecure Permissions, CWE-668 Exposure of Resource to Wrong Sphere

CVSSv3:
  • Base Score: MEDIUM (5.5)
  • Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:1.8/RC:R/MAV:A
CVSSv2:
  • Base Score: LOW (1.9)
  • Vector: /AV:L/AC:M/Au:N/C:P/I:N/A:N

References:

Vulnerable Software & Versions: (show all)

CVE-2024-47535  

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. An unsafe reading of environment file could potentially cause a denial of service in Netty. When loaded on an Windows application, Netty attempts to load a file that does not exist. If an attacker creates such a large file, the Netty application crashes. This vulnerability is fixed in 4.1.115.
CWE-400 Uncontrolled Resource Consumption

CVSSv3:
  • Base Score: MEDIUM (5.5)
  • Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:1.8/RC:R/MAV:A

References:

Vulnerable Software & Versions:

CVE-2025-25193  

Netty, an asynchronous, event-driven network application framework, has a vulnerability in versions up to and including 4.1.118.Final. An unsafe reading of environment file could potentially cause a denial of service in Netty. When loaded on an Windows application, Netty attempts to load a file that does not exist. If an attacker creates such a large file, the Netty application crash. A similar issue was previously reported as CVE-2024-47535. This issue was fixed, but the fix was incomplete in that null-bytes were not counted against the input limit. Commit d1fbda62d3a47835d3fb35db8bd42ecc205a5386 contains an updated fix.
CWE-400 Uncontrolled Resource Consumption

CVSSv3:
  • Base Score: MEDIUM (5.5)
  • Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:1.8/RC:R/MAV:A

References:

Vulnerable Software & Versions:

CVE-2024-29025  

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `HttpPostRequestDecoder` can be tricked to accumulate data. While the decoder can store items on the disk if configured so, there are no limits to the number of fields the form can have, an attacher can send a chunked post consisting of many small fields that will be accumulated in the `bodyListHttpData` list. The decoder cumulates bytes in the `undecodedChunk` buffer until it can decode a field, this field can cumulate data without limits. This vulnerability is fixed in 4.1.108.Final.
CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: MEDIUM (5.3)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions:

CVE-2026-41417  

Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')

CVSSv3:
  • Base Score: MEDIUM (5.3)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-47244  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, DefaultHttp2Connection.DefaultEndpoint initialises maxActiveStreams/maxStreams to Integer.MAX_VALUE, and Http2Settings never inserts SETTINGS_MAX_CONCURRENT_STREAMS by default (Http2Settings.java:305-307 only clamps a user-supplied value). Unless the application explicitly calls initialSettings().maxConcurrentStreams(n), a Netty HTTP/2 server advertises no limit and enforces none locally. Each open stream allocates a DefaultStream object, PropertyMap slots, flow-controller state and IntObjectHashMap entry; with ~2^30 permissible odd stream IDs a single TCP connection can create hundreds of thousands of long-lived stream objects. This is also the precondition for CVE-2023-44487-style Rapid-Reset amplification, where the absence of a low concurrent cap multiplies backend work. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-400 Uncontrolled Resource Consumption

CVSSv3:
  • Base Score: MEDIUM (5.3)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-50020  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, before reading the first request-line, `HttpObjectDecoder` skips every byte for which `Character.isISOControl(b)` is `true` (0x00–0x1F and 0x7F) as well as all whitespace. RFC 9112 §2.2 only asks servers to ignore empty CRLF lines preceding the request-line — a carefully scoped robustness allowance intended to handle HTTP/1.0 POST workarounds. Silently absorbing NUL bytes, SOH, STX, and other non-CRLF control characters goes significantly beyond this, and can be exploited for request-boundary confusion in pipelined or multiplexed transports where a front-end component treats those bytes differently. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

CVSSv3:
  • Base Score: MEDIUM (5.3)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-45536  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, netty_unix_socket_recvFd sets msg_control to `char control[CMSG_SPACE(sizeof(int))]` (line 940) — 24 bytes on 64-bit Linux. A peer-sent SCM_RIGHTS cmsg carrying two ints has cmsg_len = CMSG_LEN(8) = 24, which fits exactly with no MSG_CTRUNC, so the kernel installs both fds in the receiving process. The subsequent check `cmsg->cmsg_len == CMSG_LEN(sizeof(int))` (line 972, expected 20) fails, the branch that would read the fd is skipped, and neither installed fd is closed. The for(;;) loop calls recvmsg again (non-blocking → EAGAIN → Java maps to 0 → read loop exits normally), leaving two leaked fds per message. There is no MSG_CTRUNC handling. Reachable via Epoll/KQueue DomainSocketChannel when the application opts into DomainSocketReadMode.FILE_DESCRIPTORS (non-default). Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor, CWE-772 Missing Release of Resource after Effective Lifetime

CVSSv3:
  • Base Score: MEDIUM (4.0)
  • Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:2.5/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2025-58056  

Netty is an asynchronous event-driven network application framework for development of maintainable high performance protocol servers and clients. In versions 4.1.124.Final, and 4.2.0.Alpha3 through 4.2.4.Final, Netty incorrectly accepts standalone newline characters (LF) as a chunk-size line terminator, regardless of a preceding carriage return (CR), instead of requiring CRLF per HTTP/1.1 standards. When combined with reverse proxies that parse LF differently (treating it as part of the chunk extension), attackers can craft requests that the proxy sees as one request but Netty processes as two, enabling request smuggling attacks. This is fixed in versions 4.1.125.Final and 4.2.5.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

CVSSv4:
  • Base Score: LOW (2.9)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42578  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection'), CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')

CVSSv4:
  • Base Score: LOW (2.9)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

netty-transport-classes-epoll-4.1.123.Final.jar

Description:

Netty is an asynchronous event-driven network application framework for    rapid development of maintainable high performance protocol servers and    clients.

License:

https://www.apache.org/licenses/LICENSE-2.0
File Path: /home/grprdist/.m2/repository/io/netty/netty-transport-classes-epoll/4.1.123.Final/netty-transport-classes-epoll-4.1.123.Final.jar
MD5: cf757b6a1a2e932b0afa04f45c65aeb4
SHA1: 5a1ba263146540ffa74910edadf2475454fee927
SHA256:3db30bbaba004f86221bb251168d9bbbd38eecefb42c7802b9cbca628331e156
Referenced In Project/Scope: Grouper UI:compile
netty-transport-classes-epoll-4.1.123.Final.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

CVE-2026-45674  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS responses. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-345 Insufficient Verification of Data Authenticity, CWE-346 Origin Validation Error

CVSSv3:
  • Base Score: CRITICAL (10.0)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-47691  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's `DnsResolveContext` insufficiently validates the bailiwick of NS records, enabling DNS Cache Poisoning. An attacker controlling an authoritative name server for a subdomain can poison the cache for parent domains (like `.co.uk`). In `io.netty.resolver.dns.DnsResolveContext.AuthoritativeNameServerList#add` method accepts any NS record from the AUTHORITY section as long as the record's name is a suffix of the questionName. Subsequently, the `handleWithAdditional` method caches the associated A records from the ADDITIONAL section directly into the `authoritativeDnsServerCache` under the parent domain's key. This bypasses standard bailiwick rules, where a server authoritative for a subdomain should not be trusted to provide authoritative records for its parent. The poisoned cache is then used for all future resolutions under the parent domain's key. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-345 Insufficient Verification of Data Authenticity, CWE-346 Origin Validation Error

CVSSv3:
  • Base Score: CRITICAL (10.0)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42581  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

CVSSv3:
  • Base Score: CRITICAL (9.8)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42579  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirectional attack surface: malicious DNS responses can exploit the decoder, and user-influenced hostnames can exploit the encoder. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-20 Improper Input Validation, CWE-626 Null Byte Interaction Error (Poison Null Byte), CWE-1286 Improper Validation of Syntactic Correctness of Input

CVSSv3:
  • Base Score: CRITICAL (9.1)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42584  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

CVSSv3:
  • Base Score: CRITICAL (9.1)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-56820  

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final, `OcspClient` does not validate that the `CertificateID` in an OCSP response matches the requested `CertificateID`, which can lead to replay attack. `OcspClient.validateResponse` accepts a legitimately signed `GOOD` status response for an unrelated certificate issued by the same CA, allowing bypass of revocation checks for another certificate. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-295 Improper Certificate Validation

CVSSv3:
  • Base Score: CRITICAL (9.1)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-33871  

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv4:
  • Base Score: HIGH (8.7)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-48006  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the RedisArrayAggregator handler permanently leaks pooled direct-memory buffers when a Redis pipeline connection closes before a RESP array aggregate completes. The handler retains child messages in per-handler state (`depths` field) but defines no `channelInactive`, `handlerRemoved`, or `exceptionCaught` method to release them when the pipeline tears down. Because the leaked buffers are slices of `PooledByteBufAllocator` chunks, they prevent those chunks from being returned to the JVM-wide direct-memory pool. Repeated connection churn by any network peer monotonically drains this shared pool, eventually causing allocation failures on all Netty channels in the process. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-401 Missing Release of Memory after Effective Lifetime, CWE-772 Missing Release of Resource after Effective Lifetime

CVSSv4:
  • Base Score: HIGH (8.7)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-48059  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the HAProxy PROXY protocol v2 codec in netty leaks native or heap memory on every connection when a client sends a syntactically valid header containing nested `PP2_TYPE_SSL` TLVs (type-length-value records) at depth two or greater. The leak occurs on the successful parse path — no exception is thrown, the message fires downstream, the decoder removes itself, and the application releases the `HAProxyMessage` normally. Yet the underlying cumulation buffer (a pooled, potentially direct `ByteBuf` allocated by the channel) remains permanently pinned. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-401 Missing Release of Memory after Effective Lifetime, CWE-1286 Improper Validation of Syntactic Correctness of Input

CVSSv4:
  • Base Score: HIGH (8.7)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-55851  

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final up to (but not including) 4.2.16.Final, and 4.1.0.Final up to (but not including) 4.1.135, the `HAProxyMessageDecoder` in Netty's `codec-haproxy` module performs protocol version detection by reading the 13th byte as a signed Java `byte` and widening it to `int` without masking; a PROXY protocol v2 binary prefix followed by version byte `0xFF` sign-extends to `-1`, collides with the decoder's need-more-data sentinel, and causes `ByteToMessageDecoder` to accumulate inbound bytes in an unbounded `cumulation` buffer until direct memory is exhausted. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-400 Uncontrolled Resource Consumption

CVSSv4:
  • Base Score: HIGH (8.7)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-56745  

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, the `SpdyHttpDecoder` handler in Netty's SPDY-to-HTTP codec allocates a pooled `ByteBuf` when processing a client-initiated `SYN_STREAM` frame with `FLAG_FIN=0` and stores the partially constructed `FullHttpRequest` in `messageMap`; when the remote peer sends `RST_STREAM` for that stream or the accumulated content exceeds `maxContentLength`, the decoder removes the entry but does not release the pooled `ByteBuf`, causing native memory exhaustion. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-400 Uncontrolled Resource Consumption

CVSSv4:
  • Base Score: HIGH (8.7)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-56817  

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, any caller that can deliver bytes to a Netty channel pipeline containing `XmlDecoder` can send XML with a `DOCTYPE` declaration to an `AsyncXMLInputFactory` instantiated with no security configuration, leaving DTD and entity handling active depending on Aalto XML async parser behavior and creating conditional XML external entity risk. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-611 Improper Restriction of XML External Entity Reference

CVSSv4:
  • Base Score: HIGH (8.3)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: CRITICAL (9.8)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2025-55163  

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.124.Final and 4.2.4.Final, Netty is vulnerable to MadeYouReset DDoS. This is a logical vulnerability in the HTTP/2 protocol, that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit - which results in resource exhaustion and distributed denial of service. This issue has been patched in versions 4.1.124.Final and 4.2.4.Final.
CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv4:
  • Base Score: HIGH (8.2)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-44249  

Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-697 Incorrect Comparison, CWE-1287 Improper Validation of Specified Type of Input, CWE-284 Improper Access Control

CVSSv3:
  • Base Score: HIGH (8.1)
  • Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:2.2/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-33870  

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42583  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42585  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42587  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-44248  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion. This can cause high resource usage in both CPU and memory. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-44250  

Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can cause DoS by sending a crafted Redis payload with deeply nested arrays. This forces the server to allocate a massive number of state objects and collections, leading to memory exhaustion and an OutOfMemoryError. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-44890  

Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can cause DoS by sending crafted Redis payloads across multiple connections without `\r\n`. This exhausts the server's direct memory pool (OutOfDirectMemoryError), preventing legitimate connections from being processed. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-44891  

Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.stomp.StompSubframeDecoder fails to limit the total number of headers or their cumulative size per frame, and the maxLineLength parameter only restricts individual header lines. An attacker can send a large number of short headers that are accumulated in memory inside DefaultStompHeadersSubframe until the JVM throws an OutOfMemoryError, causing denial of service for servers exposing a STOMP endpoint based on StompSubframeDecoder. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-44893  

Netty is a network application framework for development of protocol servers and clients. In netty-codec-haproxy prior to versions 4.1.135.Final and 4.2.15.Final, when decoding a PP2_TYPE_SSL TLV, HAProxyMessage.readNextTLV() first calls `header.retainedSlice(header.readerIndex(), length)` and only then reads the 1-byte client field and 4-byte verify field. If the attacker sets the TLV length below 5, the subsequent readByte/readInt throws IndexOutOfBoundsException. HAProxyMessageDecoder only catches HAProxyProtocolException around this call, so the IOOBE propagates and the retained slice on the pooled cumulation buffer is never released. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-703 Improper Check or Handling of Exceptional Conditions, CWE-805 Buffer Access with Incorrect Length Value

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-45416  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SslClientHelloHandler.decode() reads the 24-bit TLS handshake length and, when the ClientHello does not fit in the first record, eagerly allocates `ctx.alloc().buffer(handshakeLength)` (line 161). The guard at line 140 is `handshakeLength > maxClientHelloLength && maxClientHelloLength != 0`, and the commonly-used SniHandler/AbstractSniHandler constructors (SniHandler(Mapping), SniHandler(AsyncMapping), AbstractSniHandler()) pass maxClientHelloLength=0 and handshakeTimeoutMillis=0, so the length guard is disabled and no timeout is scheduled. A 16 MiB request exceeds the default pooled chunk size and becomes a huge/unpooled allocation performed immediately. The buffer is retained in the handler until the channel closes. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-46340  

Netty is a network application framework for development of protocol servers and clients. In versions of netty-transport-sctp prior to 4.1.135.Final and 4.2.15.Final, for each non-complete SctpMessage fragment the handler does `fragments.put(streamId, Unpooled.wrappedBuffer(frag, byteBuf))`, wrapping the previous accumulator and the new slice into a *new* CompositeByteBuf every time. After N fragments the accumulator is an N-deep chain of composites, each holding references and component arrays; readableBytes()/getBytes() on the final buffer recurse N levels. There is no limit on N, on total bytes, or on the number of streamIdentifiers an attacker can open (each gets its own map entry). A peer that never sets the `complete` flag can grow this structure indefinitely from tiny 1-byte DATA chunks. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-48043  

Netty is a network application framework for development of protocol servers and clients. In netty-codec-http2 prior to versions 4.1.135.Final and 4.2.15.Final, the `DelegatingDecompressorFrameListener` class orchestrates HTTP/2 decompression by embedding a per-stream `EmbeddedChannel` that runs the appropriate decompression codec (gzip, deflate, zstd) and forwards decompressed chunks to a wrapped listener. Each decompressed chunk is a pooled `ByteBuf` handed to an anonymous `ChannelInboundHandlerAdapter` tail handler, which becomes the sole owner responsible for releasing it. A remote peer could send frames that would result in the flow-controller throwing and so trigger a resource leak which at the end might take down the whole JVM due OOME. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-400 Uncontrolled Resource Consumption, CWE-401 Missing Release of Memory after Effective Lifetime, CWE-772 Missing Release of Resource after Effective Lifetime

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-50010  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SimpleTrustManagerFactory.engineGetTrustManagers() and related paths wrap any user-supplied plain X509TrustManager in X509TrustManagerWrapper, which extends X509ExtendedTrustManager but implements the 3-arg checkServerTrusted(chain, authType, SSLEngine) by discarding the SSLEngine and calling the 2-arg delegate. Because the object now IS an X509ExtendedTrustManager, neither SunJSSE's internal AbstractTrustManagerWrapper nor Netty's own OpenSslX509TrustManagerWrapper will re-wrap it to add endpoint-identification. Consequently, even though Netty 4.2 sets endpointIdentificationAlgorithm="HTTPS" by default, a client built with `SslContextBuilder.forClient().trustManager(somePlainX509TrustManager)` performs no hostname verification at all. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-347 Improper Verification of Cryptographic Signature

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-50011  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, RedisArrayAggregator pre-allocates ArrayList with initial capacity equal to the RESP array element count declared in an array header. That count is taken from the wire before the corresponding child messages exist. A small malicious header can claim a huge initial capacity. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-55831  

Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length limit and materializes every unique setting ID in `DefaultSpdySettingsFrame`, allowing a remote SPDY/3.1 peer to send a syntactically valid roughly 2 MiB SETTINGS frame that creates 262144 map entries and amplifies network input into heap growth and ordered-map insertion work. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-55833  

Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has exceeded `maxHeaderSize` and marked the frame truncated in `SpdyFrameCodec`, allowing a remote peer to send a small compressed `HEADERS` block that expands into much larger raw header data and causes compression-amplified CPU and allocation churn. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-400 Uncontrolled Resource Consumption

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-56816  

Netty is a network application framework for development of protocol servers and clients. Prior to 4.2.16.Final, Netty's `Http3FrameCodec` buffers incoming data for HTTP/3 reserved frame types up to the wire-specified payload length without limits; `decodeFrame` trusts `payLoadLength`, allowing an attacker to open multiple QUIC streams and send reserved frames with very large payload lengths to cause memory exhaustion and denial of service. This issue is fixed in version 4.2.16.Final.
CWE-400 Uncontrolled Resource Consumption

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions:

CVE-2026-56819  

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, a remote unauthenticated peer can leak one direct `ByteBuf` per HTTP/2 `DATA` frame in applications that enable HTTP/2 content decompression via `DelegatingDecompressorFrameListener`. When a `DATA` frame is processed for a stream whose decompressor has already been closed, `Http2Decompressor.decompress(...)` calls `decompressor.writeInbound(data.retain())` and does not release the retained buffer on the error path, eventually exhausting direct memory and crashing the JVM. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-400 Uncontrolled Resource Consumption, CWE-401 Missing Release of Memory after Effective Lifetime

CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42586  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to the network output buffer without validating or sanitizing CRLF (\r\n) characters. Since the Redis Serialization Protocol (RESP) uses CRLF as the command/response delimiter, an attacker who can control the content of a Redis message can inject arbitrary Redis commands or forge fake responses. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')

CVSSv3:
  • Base Score: HIGH (7.1)
  • Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:1.8/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2025-58057  

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In netty-codec-compression versions 4.1.124.Final and below, and netty-codec versions 4.2.4.Final and below, when supplied with specially crafted input, BrotliDecoder and certain other decompression decoders will allocate a large number of reachable byte buffers, which can lead to denial of service. BrotliDecoder.decompress has no limit in how often it calls pull, decompressing data 64K bytes at a time. The buffers are saved in the output list, and remain reachable until OOM is hit. This is fixed in versions 4.1.125.Final of netty-codec and 4.2.5.Final of netty-codec-compression.
CWE-409 Improper Handling of Highly Compressed Data (Data Amplification)

CVSSv4:
  • Base Score: MEDIUM (6.9)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-50560  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty HTTP/2 max header size handling produces an attack similar to HTTP/2 Rapid Reset. There is a setting in the http2 specification called `SETTINGS_MAX_HEADER_LIST_SIZE`. When a client sends that setting to Netty, it appears that Netty will behave as follows: read the request; proxy the request to the origin; attempt to produce a response; and create an exception while writing the headers for the response. Functionally, this should be similar to the http2 reset attack, but with a different on-the-wire signature. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-770 Allocation of Resources Without Limits or Throttling

CVSSv4:
  • Base Score: MEDIUM (6.9)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: MEDIUM (5.3)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-45673  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DNS resolver uses a predictable PRNG for generating DNS transaction IDs and defaults to a static UDP source port. This combination reduces the entropy of DNS queries, enabling DNS Cache Poisoning (Kaminsky attack). Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-340 Generation of Predictable Numbers or Identifiers, CWE-330 Use of Insufficiently Random Values

CVSSv3:
  • Base Score: MEDIUM (6.8)
  • Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N/E:2.2/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2025-67735  

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')

CVSSv3:
  • Base Score: MEDIUM (6.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42580  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-190 Integer Overflow or Wraparound

CVSSv3:
  • Base Score: MEDIUM (6.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-56746  

Netty is a network application framework for development of protocol servers and clients. Versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, are vulnerable to security control bypass during the origin evaluation process. CorsHandler provides a shortCircuit() configuration designed to reject unauthorized cross-origin requests immediately, acting as a security control before requests reach the application. However, due to a logical operator error in the origin evaluation process, this protection can be entirely bypassed. An attacker can bypass the short-circuit mechanism by sending a request with an Origin: null header. This failure forwards unauthorized requests to the backend application, bypassing intended access controls. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CWE-284 Improper Access Control

CVSSv3:
  • Base Score: MEDIUM (6.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N/E:2.8/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-41417  

Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')

CVSSv3:
  • Base Score: MEDIUM (5.3)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-47244  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, DefaultHttp2Connection.DefaultEndpoint initialises maxActiveStreams/maxStreams to Integer.MAX_VALUE, and Http2Settings never inserts SETTINGS_MAX_CONCURRENT_STREAMS by default (Http2Settings.java:305-307 only clamps a user-supplied value). Unless the application explicitly calls initialSettings().maxConcurrentStreams(n), a Netty HTTP/2 server advertises no limit and enforces none locally. Each open stream allocates a DefaultStream object, PropertyMap slots, flow-controller state and IntObjectHashMap entry; with ~2^30 permissible odd stream IDs a single TCP connection can create hundreds of thousands of long-lived stream objects. This is also the precondition for CVE-2023-44487-style Rapid-Reset amplification, where the absence of a low concurrent cap multiplies backend work. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-400 Uncontrolled Resource Consumption

CVSSv3:
  • Base Score: MEDIUM (5.3)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-50020  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, before reading the first request-line, `HttpObjectDecoder` skips every byte for which `Character.isISOControl(b)` is `true` (0x00–0x1F and 0x7F) as well as all whitespace. RFC 9112 §2.2 only asks servers to ignore empty CRLF lines preceding the request-line — a carefully scoped robustness allowance intended to handle HTTP/1.0 POST workarounds. Silently absorbing NUL bytes, SOH, STX, and other non-CRLF control characters goes significantly beyond this, and can be exploited for request-boundary confusion in pipelined or multiplexed transports where a front-end component treats those bytes differently. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

CVSSv3:
  • Base Score: MEDIUM (5.3)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-45536  

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, netty_unix_socket_recvFd sets msg_control to `char control[CMSG_SPACE(sizeof(int))]` (line 940) — 24 bytes on 64-bit Linux. A peer-sent SCM_RIGHTS cmsg carrying two ints has cmsg_len = CMSG_LEN(8) = 24, which fits exactly with no MSG_CTRUNC, so the kernel installs both fds in the receiving process. The subsequent check `cmsg->cmsg_len == CMSG_LEN(sizeof(int))` (line 972, expected 20) fails, the branch that would read the fd is skipped, and neither installed fd is closed. The for(;;) loop calls recvmsg again (non-blocking → EAGAIN → Java maps to 0 → read loop exits normally), leaving two leaked fds per message. There is no MSG_CTRUNC handling. Reachable via Epoll/KQueue DomainSocketChannel when the application opts into DomainSocketReadMode.FILE_DESCRIPTORS (non-default). Versions 4.1.135.Final and 4.2.15.Final patch the issue.
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor, CWE-772 Missing Release of Resource after Effective Lifetime

CVSSv3:
  • Base Score: MEDIUM (4.0)
  • Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:2.5/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2025-58056  

Netty is an asynchronous event-driven network application framework for development of maintainable high performance protocol servers and clients. In versions 4.1.124.Final, and 4.2.0.Alpha3 through 4.2.4.Final, Netty incorrectly accepts standalone newline characters (LF) as a chunk-size line terminator, regardless of a preceding carriage return (CR), instead of requiring CRLF per HTTP/1.1 standards. When combined with reverse proxies that parse LF differently (treating it as part of the chunk extension), attackers can craft requests that the proxy sees as one request but Netty processes as two, enabling request smuggling attacks. This is fixed in versions 4.1.125.Final and 4.2.5.Final.
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

CVSSv4:
  • Base Score: LOW (2.9)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

CVE-2026-42578  

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection'), CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')

CVSSv4:
  • Base Score: LOW (2.9)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

nimbus-jose-jwt-10.6.jar (shaded: com.google.code.gson:gson:2.13.1)

License:

Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/com/nimbusds/nimbus-jose-jwt/10.6/nimbus-jose-jwt-10.6.jar/META-INF/maven/com.google.code.gson/gson/pom.xml
MD5: dcd6122810df12e276edc375730f7a9b
SHA1: 75c68fafbbc6c1abc95a60a5953cac165e102d5a
SHA256:c0f65722d75c0e58cd1835b3046046f606b5da699904161f8db6b78feb9b401a
Referenced In Project/Scope: Grouper UI:compile

Identifiers

nimbus-jose-jwt-10.6.jar

Description:

        Java library for Javascript Object Signing and Encryption (JOSE) and
        JSON Web Tokens (JWT)
    

License:

The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/com/nimbusds/nimbus-jose-jwt/10.6/nimbus-jose-jwt-10.6.jar
MD5: 29a05ec4aa6b46b8d8dee66701052108
SHA1: 6c0b9c9b420ec7def22994c839ca85969e4e68ff
SHA256:7ef3b0dd4a27407639d469cd75e7770463b4ee36e2c13535465da175d3b8f964
Referenced In Project/Scope: Grouper UI:compile
nimbus-jose-jwt-10.6.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

oauth2-oidc-sdk-11.30.1.jar

Description:

		OAuth 2.0 SDK with OpenID Connection extensions for developing client
		and server applications.
	

License:

Apache License, version 2.0: https://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/grprdist/.m2/repository/com/nimbusds/oauth2-oidc-sdk/11.30.1/oauth2-oidc-sdk-11.30.1.jar
MD5: 67ef8ff7e65d04b04b88a432c8996d2b
SHA1: c6aaadc7567a22da3c10168e6b953e67f1541d97
SHA256:b671d28e2ebb3b01848a0811d366e687c618ffd467b9d5a1536f5f93c449ed61
Referenced In Project/Scope: Grouper UI:compile
oauth2-oidc-sdk-11.30.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

opentest4j-1.3.0.jar

Description:

Open Test Alliance for the JVM

License:

The Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/org/opentest4j/opentest4j/1.3.0/opentest4j-1.3.0.jar
MD5: 03c404f727531f3fd3b4c73997899327
SHA1: 152ea56b3a72f655d4fd677fc0ef2596c3dd5e6e
SHA256:48e2df636cab6563ced64dcdff8abb2355627cb236ef0bf37598682ddf742f1b
Referenced In Project/Scope: Grouper UI:compile
opentest4j-1.3.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

org.apache.felix.framework-7.0.5.jar

Description:

OSGi R8 framework implementation.

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/org/apache/felix/org.apache.felix.framework/7.0.5/org.apache.felix.framework-7.0.5.jar
MD5: 82e51fdc1bde2a02d69d6310a02a4620
SHA1: dd4cb10c68d9ceb7897e561be7c4c16d25347193
SHA256:aba72932c5ffe52d1ae9fb735415474bc8305fd04f050e851f3a8f67da1834fd
Referenced In Project/Scope: Grouper UI:compile
org.apache.felix.framework-7.0.5.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

oro-2.0.8.jar

File Path: /home/grprdist/.m2/repository/oro/oro/2.0.8/oro-2.0.8.jar
MD5: 42e940d5d2d822f4dc04c65053e630ab
SHA1: 5592374f834645c4ae250f4c9fbb314c9369d698
SHA256:e00ccdad5df7eb43fdee44232ef64602bf63807c2d133a7be83ba09fd49af26e
Referenced In Project/Scope: Grouper UI:compile
oro-2.0.8.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

picocli-4.3.2.jar

Description:

Java command line parser with both an annotations API and a programmatic API. Usage help with ANSI styles and colors. Autocomplete. Nested subcommands. Easily included as source to avoid adding a dependency.

License:

The Apache Software License, version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/info/picocli/picocli/4.3.2/picocli-4.3.2.jar
MD5: f20bf12b29c0ffea894d557336171f39
SHA1: 37a9ed41f7a028611775b6e8ad831e3e5fcd6280
SHA256:43c9cf516012aad1ac5ce6b54642e9cb1271e66d827b06a879fd314144d57550
Referenced In Project/Scope: Grouper UI:compile
picocli-4.3.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

playwright-1.57.0.jar

Description:

Java library to automate Chromium, Firefox and WebKit with a single API.
    Playwright is built to enable cross-browser web automation that is ever-green, capable,
    reliable and fast.

    This is the main package that provides Playwright client.
  

File Path: /home/grprdist/.m2/repository/com/microsoft/playwright/playwright/1.57.0/playwright-1.57.0.jar
MD5: 669439b313821046332cec7a6c4d30b3
SHA1: 03fad536566f861ef8a163c6a9d64a8884835831
SHA256:4c1e655f5c2238f06498c6a335d2e32ab5aaa24e2bd81b7fd8e646d8ac02318d
Referenced In Project/Scope: Grouper UI:compile
playwright-1.57.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

postgresql-42.7.11.jar

Description:

PostgreSQL JDBC Driver Postgresql

License:

BSD-2-Clause: https://jdbc.postgresql.org/about/license.html
File Path: /home/grprdist/.m2/repository/org/postgresql/postgresql/42.7.11/postgresql-42.7.11.jar
MD5: b969f87f07d6434bd77cdc5e440da49a
SHA1: 4c21cdd1b3938f400703716d37c4e8ca4d332808
SHA256:1981b31d3993c58702783c1cddf10a34e48c1f413d70ff1cb6def0a143484647
Referenced In Project/Scope: Grouper UI:runtime
postgresql-42.7.11.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper-ui@7.0.0-SNAPSHOT

Identifiers

CVE-2026-54291  

pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with channel binding to plain SCRAM-SHA-256 without it, losing the man-in-the-middle protection the setting is meant to guarantee. An attacker who can intercept the TLS connection can trigger the downgrade with a certificate whose signature algorithm has no tls-server-end-point channel-binding hash, because the bundled com.ongres.scram:scram-client returns an empty byte array instead of failing and pgJDBC ScramAuthenticator checks only that the server advertised a PLUS mechanism, without rejecting the empty binding or checking that the negotiated mechanism uses channel binding. This issue is fixed in version 42.7.12.
CWE-636 Not Failing Securely ('Failing Open'), CWE-757 Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')

CVSSv4:
  • Base Score: HIGH (8.2)
  • Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: MEDIUM (5.9)
  • Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N/E:2.2/RC:R/MAV:A

References:

Vulnerable Software & Versions:

protobuf-java-4.31.1.jar

Description:

    Core Protocol Buffers library. Protocol Buffers are a way of encoding structured data in an
    efficient yet extensible format.
  

License:

https://opensource.org/licenses/BSD-3-Clause
File Path: /home/grprdist/.m2/repository/com/google/protobuf/protobuf-java/4.31.1/protobuf-java-4.31.1.jar
MD5: 4987ffc8ba1965e5546bdcf49dcfffe2
SHA1: 1828b20315b63d5f71b3c61b094494a8f1acdc5a
SHA256:d60dfe7c68a0d38a248cca96924f289dc7e1966a887ee7cae397701af08575ae
Referenced In Project/Scope: Grouper UI:runtime
protobuf-java-4.31.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.mysql/mysql-connector-j@9.5.0

Identifiers

CVE-2026-0994  

A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages.

Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError.
CWE-674 Uncontrolled Recursion

CVSSv4:
  • Base Score: HIGH (8.2)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X
CVSSv3:
  • Base Score: HIGH (7.5)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A

References:

Vulnerable Software & Versions:

proton-j-0.33.10.jar

Description:

Proton is a library for speaking AMQP.

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/org/apache/qpid/proton-j/0.33.10/proton-j-0.33.10.jar
MD5: 55d0529cb097f647e53cff7a4189b128
SHA1: fb31048dec7642e31982a46500acb211f52f6314
SHA256:1fcddf5c76e70eff331900443c51e1a2c8d313b5ffc70611995fadfb6c36d96a
Referenced In Project/Scope: Grouper UI:compile
proton-j-0.33.10.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

qpid-jms-client-0.61.0.jar

Description:

The core JMS Client implementation

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/org/apache/qpid/qpid-jms-client/0.61.0/qpid-jms-client-0.61.0.jar
MD5: e8bd7c8a71cdcebbd6701084d4caae11
SHA1: f53f49713a144de8e46cffb4af24a1775dea1e0c
SHA256:7aea6f78c010c34cce82de3f837ccf17362c4d05588bd2d0af6e938de575ca0b
Referenced In Project/Scope: Grouper UI:compile
qpid-jms-client-0.61.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

quartz-2.5.2.jar

Description:

Quartz Enterprise Job Scheduler

License:

The Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/org/quartz-scheduler/quartz/2.5.2/quartz-2.5.2.jar
MD5: b8ed3623018a763841145b5afce13230
SHA1: 2c3a3d8dc34774607e73370352bb1c1beb82b71a
SHA256:452e418739c0da1bff255f7c1343dd3a92e1fdd3ceb126b185939edae9922091
Referenced In Project/Scope: Grouper UI:compile
quartz-2.5.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper-ui@7.0.0-SNAPSHOT

Identifiers

slf4j-api-1.7.36.jar

Description:

The slf4j API

File Path: /home/grprdist/.m2/repository/org/slf4j/slf4j-api/1.7.36/slf4j-api-1.7.36.jar
MD5: 872da51f5de7f3923da4de871d57fd85
SHA1: 6c62681a2f655b49963a5983b8b0950a6120ae14
SHA256:d3ef575e3e4979678dc01bf1dcce51021493b4d11fb7f1be8ad982877c16a1c0
Referenced In Project/Scope: Grouper UI:compile
slf4j-api-1.7.36.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper-ui@7.0.0-SNAPSHOT

Identifiers

smack-3.1.0.jar

Description:

        Smack is an Open Source XMPP (Jabber) client library for instant messaging and presence. A pure Java library, it can be embedded into your applications to create anything from a full XMPP client to simple XMPP integrations such as sending notification messages.
    

License:

Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0
File Path: /home/grprdist/.m2/repository/jivesoftware/smack/3.1.0/smack-3.1.0.jar
MD5: 362dd4c2fc9b23a33d47272456dd0c39
SHA1: 916a0fe08d840a08c950f49fb59b961e14d673b8
SHA256:c9a25e014608d3402b795d125c88a18a6e22e6c61c65b5e5d224e0f72f4aec8b
Referenced In Project/Scope: Grouper UI:compile
smack-3.1.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

CVE-2014-5075 (OSSINDEX)  

The Ignite Realtime Smack XMPP API 4.x before 4.0.2, and 3.x and 2.x when a custom SSLContext is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
CWE-310 Cryptographic Issues

CVSSv2:
  • Base Score: MEDIUM (6.800000190734863)
  • Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

References:

Vulnerable Software & Versions (OSSINDEX):

  • cpe:2.3:a:jivesoftware:smack:3.1.0:*:*:*:*:*:*:*

CVE-2014-0363 (OSSINDEX)  

The ServerTrustManager component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify basicConstraints and nameConstraints in X.509 certificate chains from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate chain.
CWE-295 Improper Certificate Validation

CVSSv2:
  • Base Score: MEDIUM (5.800000190734863)
  • Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

References:

Vulnerable Software & Versions (OSSINDEX):

  • cpe:2.3:a:jivesoftware:smack:3.1.0:*:*:*:*:*:*:*

standard-1.1.2.jar

File Path: /home/grprdist/.m2/repository/taglibs/standard/1.1.2/standard-1.1.2.jar
MD5: 65351d0487ad57edda9171bb3b46b98c
SHA1: a17e8a4d9a1f7fcc5eed606721c9ed6b7f18acf7
SHA256:2c0048ab3ce75a202f692b159d6aa0a68edce3e4e4c5123a3359a38b29faa6b1
Referenced In Project/Scope: Grouper UI:compile
standard-1.1.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper-ui@7.0.0-SNAPSHOT

Identifiers

CVE-2015-0254  

Apache Standard Taglibs before 1.2.3 allows remote attackers to execute arbitrary code or conduct external XML entity (XXE) attacks via a crafted XSLT extension in a (1) <x:parse> or (2) <x:transform> JSTL XML tag.
NVD-CWE-Other

CVSSv2:
  • Base Score: HIGH (7.5)
  • Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P

References:

Vulnerable Software & Versions:

stax-ex-1.8.jar

Description:

Extensions to JSR-173 StAX API.

License:

                Dual license consisting of the CDDL v1.1 and GPL v2
            : https://glassfish.dev.java.net/public/CDDL+GPL_1_1.html
File Path: /home/grprdist/.m2/repository/org/jvnet/staxex/stax-ex/1.8/stax-ex-1.8.jar
MD5: a0ebfdbc6b5a34b174a1d1f732d1bdda
SHA1: 8cc35f73da321c29973191f2cf143d29d26a1df7
SHA256:95b05d9590af4154c6513b9c5dc1fb2e55b539972ba0a9ef28e9a0c01d83ad77
Referenced In Project/Scope: Grouper UI:compile
stax-ex-1.8.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

txw2-2.3.1.jar

Description:

        TXW is a library that allows you to write XML documents.
    

File Path: /home/grprdist/.m2/repository/org/glassfish/jaxb/txw2/2.3.1/txw2-2.3.1.jar
MD5: 0fed730907ba86376ef392ee7eb42d5f
SHA1: a09d2c48d3285f206fafbffe0e50619284e92126
SHA256:34975dde1c6920f1a39791142235689bc3cd357e24d05edd8ff93b885bd68d60
Referenced In Project/Scope: Grouper UI:compile
txw2-2.3.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

xercesImpl-2.12.2.jar

Description:

      Xerces2 provides high performance, fully compliant XML parsers in the Apache Xerces family. This new version of Xerces continues to build upon the Xerces Native Interface (XNI), a complete framework for building parser components and configurations that is extremely modular and easy to program.

      The Apache Xerces2 parser is the reference implementation of XNI but other parser components, configurations, and parsers can be written using the Xerces Native Interface. For complete design and implementation documents, refer to the XNI Manual.

      Xerces2 provides fully conforming XML Schema 1.0 and 1.1 processors. An experimental implementation of the "XML Schema Definition Language (XSD): Component Designators (SCD) Candidate Recommendation (January 2010)" is also provided for evaluation. For more information, refer to the XML Schema page.

      Xerces2 also provides a complete implementation of the Document Object Model Level 3 Core and Load/Save W3C Recommendations and provides a complete implementation of the XML Inclusions (XInclude) W3C Recommendation. It also provides support for OASIS XML Catalogs v1.1.

      Xerces2 is able to parse documents written according to the XML 1.1 Recommendation, except that it does not yet provide an option to enable normalization checking as described in section 2.13 of this specification. It also handles namespaces according to the XML Namespaces 1.1 Recommendation, and will correctly serialize XML 1.1 documents if the DOM level 3 load/save APIs are in use.  
	

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/grprdist/.m2/repository/xerces/xercesImpl/2.12.2/xercesImpl-2.12.2.jar
MD5: 40e4f2d5aacfbf51a9a1572d77a0e5e9
SHA1: f051f988aa2c9b4d25d05f95742ab0cc3ed789e2
SHA256:6fc991829af1708d15aea50c66f0beadcd2cfeb6968e0b2f55c1b0909883fe16
Referenced In Project/Scope: Grouper UI:compile
xercesImpl-2.12.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

  • pkg:maven/xerces/xercesImpl@2.12.2  (Confidence:High)
  • cpe:2.3:a:apache:xerces-j:2.12.2:*:*:*:*:*:*:*  (Confidence:Low)  
  • cpe:2.3:a:apache:xerces2_java:2.12.2:*:*:*:*:*:*:*  (Confidence:Low)  

CVE-2017-7503 (OSSINDEX)  

It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use this flaw to launch DoS or SSRF attacks, or read files from the server where EAP is deployed.
CWE-611 Improper Restriction of XML External Entity Reference

CVSSv3:
  • Base Score: CRITICAL (9.800000190734863)
  • Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References:

Vulnerable Software & Versions (OSSINDEX):

  • cpe:2.3:a:xerces:xercesImpl:2.12.2:*:*:*:*:*:*:*

CVE-2017-10355 (OSSINDEX)  

sonatype-2017-0348 - xerces:xercesImpl - Denial of Service (DoS)
CWE-833 Deadlock

CVSSv3:
  • Base Score: MEDIUM (5.900000095367432)
  • Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

References:

Vulnerable Software & Versions (OSSINDEX):

  • cpe:2.3:a:xerces:xercesImpl:2.12.2:*:*:*:*:*:*:*

xmlpull-1.1.3.1.jar

License:

Public Domain: http://www.xmlpull.org/v1/download/unpacked/LICENSE.txt
File Path: /home/grprdist/.m2/repository/xmlpull/xmlpull/1.1.3.1/xmlpull-1.1.3.1.jar
MD5: cc57dacc720eca721a50e78934b822d2
SHA1: 2b8e230d2ab644e4ecaa94db7cdedbc40c805dfa
SHA256:34e08ee62116071cbb69c0ed70d15a7a5b208d62798c59f2120bb8929324cb63
Referenced In Project/Scope: Grouper UI:compile
xmlpull-1.1.3.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers

xstream-1.4.21.jar

Description:

XStream is a serialization library from Java objects to XML and back.

License:

BSD-3-Clause
File Path: /home/grprdist/.m2/repository/com/thoughtworks/xstream/xstream/1.4.21/xstream-1.4.21.jar
MD5: 767be88fc6ec4bb96e2906a17aab8e5b
SHA1: 65cb3e7f809b18b9aab43f2338ee5b320f72d7bd
SHA256:f56586f3de59ae2a49430acbc9f27942b8c5cebec9245c869fae7136733333ec
Referenced In Project/Scope: Grouper UI:compile
xstream-1.4.21.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/edu.internet2.middleware.grouper/grouper@7.0.0-SNAPSHOT

Identifiers



This report contains data retrieved from the National Vulnerability Database.
This report may contain data retrieved from the CISA Known Exploited Vulnerability Catalog.
This report may contain data retrieved from the Github Advisory Database (via NPM Audit API).
This report may contain data retrieved from RetireJS.
This report may contain data retrieved from the Sonatype OSS Index.