CVE-2016-4970: Apache Cassandra

High severity, CVSS 7.5. EPSS: 11.3% chance of exploitation in the next 30 days.

handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (infinite loop).

Affected products

  • Apache Cassandra: version 3.11.4 only
  • Netty Netty: from 4.0.20, before 4.0.37 (fixed in 4.0.37); from 4.1.0, before 4.1.1 (fixed in 4.1.1)
  • Red Hat JBoss Data Grid: version 7.1 only
  • Red Hat JBoss Middleware Text-Only Advisories: version 1.0 only

Published 2017-04-13. Last modified 2026-06-17.