云虫漏洞情报

CVE-2026-62380 - Netty (io.netty:netty-codec-socks) versions 4.2.0.Final through 4.2.16.Final and 4.1.x through 4.1.136.Final contain null byte, CRLF, and credential injection vulnerabilities in the SOCKS4 (Socks4ClientEncoder) and SOCKS5 (Socks5ClientEncoder) client encoders, which fail to validate domain address and authentication (username/password) fields. An attacker able to control these fields can inject null bytes or CRLF characters to truncate or alter values, potentially enabling domai - 漏洞详情

漏洞编号:CVE-2026-62380

风险等级:高危

漏洞来源:CVE

CVE 编号:CVE-2026-62380

CNNVD 编号:-

厂商/产品:netty / netty

影响范围:cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:*

CWE:CWE-626

发布/更新时间:2026-08-22 / 2026-08-27

漏洞描述

Netty (io.netty:netty-codec-socks) versions 4.2.0.Final through 4.2.16.Final and 4.1.x through 4.1.136.Final contain null byte, CRLF, and credential injection vulnerabilities in the SOCKS4 (Socks4ClientEncoder) and SOCKS5 (Socks5ClientEncoder) client encoders, which fail to validate domain address and authentication (username/password) fields. An attacker able to control these fields can inject null bytes or CRLF characters to truncate or alter values, potentially enabling domain spoofing, SOCKS4 userid truncation, authentication data injection, and protocol confusion. Fixed in 4.2.17.Final and 4.1.137.Final.

相关链接

相关漏洞

« 返回首页