Null Byte and Credential Injection Vulnerabilities in Netty's SOCKS Clients
CVE-2026-62380

6.3MEDIUM

Key Information:

Vendor

Netty

Status
Vendor
CVE Published:
22 August 2026

What is CVE-2026-62380?

Netty's SOCKS client encoders (both SOCKS4 and SOCKS5) are exposed to vulnerabilities due to improper validation in authentication fields and domain addresses. Attackers can exploit these weaknesses by injecting null bytes or CRLF characters, allowing for potential domain spoofing, user ID truncation, and unauthorized access through credential data manipulation. Users are advised to update to versions 4.2.17.Final or 4.1.137.Final to mitigate these risks effectively.

Affected Version(s)

netty 4.2.0.Final < 4.2.16.Final

netty 0 < 4.1.137.Final

netty 4.2.16.Final

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.