CVE Feed

    Dashboard / CVE / CVE-2025-24970

    CVE-2025-24970

    Netty, an asynchronous, event-driven network application framework, has a vulnerability starting in version 4.1.91.Final and prior to version 4.1.118.Final. When a special crafted packet is received via SslHandler it doesn't correctly handle validation of such a packet in all cases which can lead to a native crash. Version 4.1.118.Final contains a patch. As workaround its possible to either disable the usage of the native SSLEngine or change the code manually.

    Published:Feb 10, 2025
    Last Modified:Sep 5, 2025
    EPS:Feb 10, 2025
    EPSS Score:0.00216
    CVSS Score:7.5

    Affected Products

    Vendor
    Netapp
    Product
    Active Iq Unified Manager
    Vendor
    Netapp
    Product
    Oncommand Insight
    Vendor
    Netty
    Product
    Netty
    Vendor
    Redhat
    Product
    Amq Streams
    Vendor
    Redhat
    Product
    Apache Camel Hawtio
    Vendor
    Redhat
    Product
    Apache Camel Spring Boot
    Vendor
    Redhat
    Product
    Camel K
    Vendor
    Redhat
    Product
    Camel Quarkus
    Vendor
    Redhat
    Product
    Jboss Data Grid
    Vendor
    Redhat
    Product
    Jboss Enterprise Application Platform
    Vendor
    Redhat
    Product
    Openshift Ai
    Vendor
    Redhat
    Product
    Quarkus

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High