Event-Driven Network Framework Vulnerability in Netty
CVE-2026-59903
6.5MEDIUM
What is CVE-2026-59903?
Netty, an asynchronous event-driven network application framework, contains a vulnerability in the CorsHandler that incorrectly manages application Vary headers, such as Authorization or Cookie. This misconfiguration permits caching proxies or CDNs to leverage authenticated responses across different users, potentially exposing sensitive information. The issue is rectified in versions 4.1.137.Final and 4.2.17.Final, emphasizing the importance of updating to these releases to safeguard against unauthorized data access.
Affected Version(s)
netty < 4.1.137.Final < 4.1.137.Final
netty >= 4.2.0.Final, < 4.2.17.Final < 4.2.0.Final, 4.2.17.Final
