Event-Driven Network Framework Vulnerability in Netty
CVE-2026-59903

6.5MEDIUM

Key Information:

Vendor

Netty

Status
Vendor
CVE Published:
17 August 2026

What is CVE-2026-59903?

Netty, an asynchronous event-driven network application framework, contains a vulnerability in the CorsHandler that incorrectly manages application Vary headers, such as Authorization or Cookie. This misconfiguration permits caching proxies or CDNs to leverage authenticated responses across different users, potentially exposing sensitive information. The issue is rectified in versions 4.1.137.Final and 4.2.17.Final, emphasizing the importance of updating to these releases to safeguard against unauthorized data access.

Affected Version(s)

netty < 4.1.137.Final < 4.1.137.Final

netty >= 4.2.0.Final, < 4.2.17.Final < 4.2.0.Final, 4.2.17.Final

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.