CVE-2026-62380
Last modified
CVE-2026-62380 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Netty (io.netty:netty-codec-socks) versions 4.2.0.Final through 4.2.16.Final and 4.1.x through 4.1.136.Final contain null byte, CRLF, and credential injection vulnerabilities in the SOCKS4 (Socks4ClientEncoder) and SOCKS5 (Socks5ClientEncoder) client encoders, which fail to validate domain address and authentication (username/password) fields. An attacker able to control these fields can inject null bytes or CRLF characters to truncate or alter values, potentially enabling domain spoofing, SOCKS4 userid truncation, authentication data injection, and protocol confusion. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
Netty (io.netty:netty-codec-socks) versions 4.2.0.Final through 4.2.16.Final and 4.1.x through 4.1.136.Final contain null byte, CRLF, and credential injection vulnerabilities in the SOCKS4 (Socks4ClientEncoder) and SOCKS5 (Socks5ClientEncoder) client encoders, which fail to validate domain address and authentication (username/password) fields. An attacker able to control these fields can inject null bytes or CRLF characters to truncate or alter values, potentially enabling domain spoofing, SOCKS4 userid truncation, authentication data injection, and protocol confusion. Fixed in 4.2.17.Final and 4.1.137.Final.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Netty | Netty | < 4.1.137 |
| Netty | Netty | >= 4.2.0, < 4.2.17 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-62380?
How severe is CVE-2026-62380?
How do I fix CVE-2026-62380?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-62370KubeEdge is an open source system for extending native conta…6.5
- CVE-2026-62371KubeEdge is an open source system for extending native conta…8.8
- CVE-2026-62377libheif is a HEIF and AVIF file format decoder and encoder. …4.3
- CVE-2026-62378RustFS Console is a web management console for the RustFS di…9
- CVE-2026-62379Open Access Management (OpenAM) is an access management solu…9.8
- CVE-2026-6238The deprecated functions ns_printrrf, ns_printrr and fp_nque…6.5
- CVE-2026-62381luci-lib-px5g (LuCI) contains a heap-based buffer overflow i…6.6
- CVE-2026-62382PasswordPusher versions v1.45.11 through v2.9.5 contain an i…6.9
- CVE-2026-62383nltk versions before 3.10.2 contain a symlink-based arbitrar…5.5
- CVE-2026-62384NLTK versions before 3.10.2 contain a symlink-based sandbox …7.5
- CVE-2026-62385NLTK versions before 3.10.0 contain a path traversal vulnera…7.5
- CVE-2026-62386The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-r…8.2
Are you affected by CVE-2026-62380?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
