CVE-2014-0193: Netty

Medium severity, CVSS 5.0. EPSS: 4.3% chance of exploitation in the next 30 days.

WebSocket08FrameDecoder in Netty 3.6.x before 3.6.9, 3.7.x before 3.7.1, 3.8.x before 3.8.2, 3.9.x before 3.9.1, and 4.0.x before 4.0.19 allows remote attackers to cause a denial of service (memory consumption) via a TextWebSocketFrame followed by a long stream of ContinuationWebSocketFrames.

Affected products

  • Netty Netty: version 3.6.0 only; version 3.6.1 only; version 3.6.2 only; version 3.6.3 only; version 3.6.4 only; version 3.6.5 only; …

Published 2014-05-06. Last modified 2026-06-17.