-
Notifications
You must be signed in to change notification settings - Fork 2.2k
azure-core-http-netty 1.16.3 bundles Netty 4.1.130.Final, vulnerable to CVE-2026-33870 and CVE-2026-33871 #48631
Copy link
Copy link
Open
Labels
Azure.Coreazure-coreazure-coreHttpClientcustomer-reportedIssues that are reported by GitHub users external to the Azure organization.Issues that are reported by GitHub users external to the Azure organization.needs-team-attentionWorkflow: This issue needs attention from Azure service team or SDK teamWorkflow: This issue needs attention from Azure service team or SDK teamquestionThe issue doesn't require a change to the product in order to be resolved. Most issues start as thatThe issue doesn't require a change to the product in order to be resolved. Most issues start as that
Description
azure-core-http-netty 1.16.3 (the current stable release) transitively pulls in io.netty:netty-codec-http and io.netty:netty-codec-http2 at version 4.1.130.Final, which is vulnerable to two recently published CVEs:
Both were fixed in Netty 4.1.132.Final, released 2026-03-24.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
Azure.Coreazure-coreazure-coreHttpClientcustomer-reportedIssues that are reported by GitHub users external to the Azure organization.Issues that are reported by GitHub users external to the Azure organization.needs-team-attentionWorkflow: This issue needs attention from Azure service team or SDK teamWorkflow: This issue needs attention from Azure service team or SDK teamquestionThe issue doesn't require a change to the product in order to be resolved. Most issues start as thatThe issue doesn't require a change to the product in order to be resolved. Most issues start as that
Type
Projects
Status
No status