Skip to content

chore(deps): Bump netty.version from 4.2.18.Final to 4.2.19.Final - #1251

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/netty.version-4.2.19.Final
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/netty.version-4.2.19.Final

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 9, 2026

Copy link
Copy Markdown
Contributor

Bumps netty.version from 4.2.18.Final to 4.2.19.Final.
Updates io.netty:netty-codec-http from 4.2.18.Final to 4.2.19.Final

Release notes

Sourced from io.netty:netty-codec-http's releases.

netty-4.2.19.Final

Security

Note that Netty 4.1 will be End-of-Life on July 1st, 2027.

We strongly recommend upgrading to this version to get the following security fixes:

  • CVE-2026-XXXXX : parser desync in io.netty:netty-codec-haproxy
  • CVE-2026-XXXXX : improper CRLF neutralization (request/response smuggling) in io.netty:netty-codec-http
  • CVE-2026-XXXXX : origin validation error in io.netty:netty-codec-http
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-http2
  • CVE-2026-XXXXX : request/response smuggling in io.netty:netty-codec-http
  • CVE-2026-XXXXX : time-of-check/time-of-use error in io.netty:netty-handler-ssl-ocsp
  • CVE-2026-XXXXX : SNI routing bypass in io.netty:netty-handler
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-xml
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-base
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-http
  • CVE-2026-XXXXX : input misinterpretation in io.netty:netty-codec-socks
  • CVE-2026-XXXXX : improper access control in io.netty:netty-handler
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-dns
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-http3
  • CVE-2026-XXXXX : use-after-free in io.netty:netty-transport-classes-io_uring
  • CVE-2026-XXXXX : memory leak in io.netty:netty-transport-native-io_uring

Note that due to overwhelming strain on the CVE infrastructure, we have not gotten a single CVE number assigned to these reports in time for our release. The advisories will be published without.

Specific changes worth calling out:

Validation in FileUpload.setContentType. Previously, the FileUpload.setContentType methods did not validate their inputs. They now throw an IllegaalArgumentException if the given string is not formatted as a plausible MIME content type.

What's Changed

... (truncated)

Commits
  • 64cc10f [maven-release-plugin] prepare release netty-4.2.19.Final
  • e863e69 Fix io_uring domain socket fd leak on multi-fd SCM_RIGHTS messages
  • d82c6c3 Fix IP allow-list bypass from ruleType-blind dedup in IpSubnetFilter
  • bccc62a Bound domain-name decode buffer to avoid quadratic allocation
  • 6b02cd3 Fix wrong nextBid computation in IoUringBufferRing for RECVSEND_BUNDLE
  • ef3a3e1 Fix sign-extension bug in SocksInitRequestDecoder NMETHODS field
  • 4cacdf0 Fix quadratic CPU usage in XmlFrameDecoder when an element is never balanced
  • 20f3aae Fail closed on zero-length handshake records in SslClientHelloHandler
  • c3f7088 Netty OcspServerCertificateValidator still delivers buffered data from a revo...
  • 4029f07 Correctly handle multiple Content-Length
  • Additional commits viewable in compare view

Updates io.netty:netty-handler from 4.2.18.Final to 4.2.19.Final

Release notes

Sourced from io.netty:netty-handler's releases.

netty-4.2.19.Final

Security

Note that Netty 4.1 will be End-of-Life on July 1st, 2027.

We strongly recommend upgrading to this version to get the following security fixes:

  • CVE-2026-XXXXX : parser desync in io.netty:netty-codec-haproxy
  • CVE-2026-XXXXX : improper CRLF neutralization (request/response smuggling) in io.netty:netty-codec-http
  • CVE-2026-XXXXX : origin validation error in io.netty:netty-codec-http
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-http2
  • CVE-2026-XXXXX : request/response smuggling in io.netty:netty-codec-http
  • CVE-2026-XXXXX : time-of-check/time-of-use error in io.netty:netty-handler-ssl-ocsp
  • CVE-2026-XXXXX : SNI routing bypass in io.netty:netty-handler
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-xml
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-base
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-http
  • CVE-2026-XXXXX : input misinterpretation in io.netty:netty-codec-socks
  • CVE-2026-XXXXX : improper access control in io.netty:netty-handler
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-dns
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-http3
  • CVE-2026-XXXXX : use-after-free in io.netty:netty-transport-classes-io_uring
  • CVE-2026-XXXXX : memory leak in io.netty:netty-transport-native-io_uring

Note that due to overwhelming strain on the CVE infrastructure, we have not gotten a single CVE number assigned to these reports in time for our release. The advisories will be published without.

Specific changes worth calling out:

Validation in FileUpload.setContentType. Previously, the FileUpload.setContentType methods did not validate their inputs. They now throw an IllegaalArgumentException if the given string is not formatted as a plausible MIME content type.

What's Changed

... (truncated)

Commits
  • 64cc10f [maven-release-plugin] prepare release netty-4.2.19.Final
  • e863e69 Fix io_uring domain socket fd leak on multi-fd SCM_RIGHTS messages
  • d82c6c3 Fix IP allow-list bypass from ruleType-blind dedup in IpSubnetFilter
  • bccc62a Bound domain-name decode buffer to avoid quadratic allocation
  • 6b02cd3 Fix wrong nextBid computation in IoUringBufferRing for RECVSEND_BUNDLE
  • ef3a3e1 Fix sign-extension bug in SocksInitRequestDecoder NMETHODS field
  • 4cacdf0 Fix quadratic CPU usage in XmlFrameDecoder when an element is never balanced
  • 20f3aae Fail closed on zero-length handshake records in SslClientHelloHandler
  • c3f7088 Netty OcspServerCertificateValidator still delivers buffered data from a revo...
  • 4029f07 Correctly handle multiple Content-Length
  • Additional commits viewable in compare view

Updates io.netty:netty-transport from 4.2.18.Final to 4.2.19.Final

Release notes

Sourced from io.netty:netty-transport's releases.

netty-4.2.19.Final

Security

Note that Netty 4.1 will be End-of-Life on July 1st, 2027.

We strongly recommend upgrading to this version to get the following security fixes:

  • CVE-2026-XXXXX : parser desync in io.netty:netty-codec-haproxy
  • CVE-2026-XXXXX : improper CRLF neutralization (request/response smuggling) in io.netty:netty-codec-http
  • CVE-2026-XXXXX : origin validation error in io.netty:netty-codec-http
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-http2
  • CVE-2026-XXXXX : request/response smuggling in io.netty:netty-codec-http
  • CVE-2026-XXXXX : time-of-check/time-of-use error in io.netty:netty-handler-ssl-ocsp
  • CVE-2026-XXXXX : SNI routing bypass in io.netty:netty-handler
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-xml
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-base
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-http
  • CVE-2026-XXXXX : input misinterpretation in io.netty:netty-codec-socks
  • CVE-2026-XXXXX : improper access control in io.netty:netty-handler
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-dns
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-http3
  • CVE-2026-XXXXX : use-after-free in io.netty:netty-transport-classes-io_uring
  • CVE-2026-XXXXX : memory leak in io.netty:netty-transport-native-io_uring

Note that due to overwhelming strain on the CVE infrastructure, we have not gotten a single CVE number assigned to these reports in time for our release. The advisories will be published without.

Specific changes worth calling out:

Validation in FileUpload.setContentType. Previously, the FileUpload.setContentType methods did not validate their inputs. They now throw an IllegaalArgumentException if the given string is not formatted as a plausible MIME content type.

What's Changed

... (truncated)

Commits
  • 64cc10f [maven-release-plugin] prepare release netty-4.2.19.Final
  • e863e69 Fix io_uring domain socket fd leak on multi-fd SCM_RIGHTS messages
  • d82c6c3 Fix IP allow-list bypass from ruleType-blind dedup in IpSubnetFilter
  • bccc62a Bound domain-name decode buffer to avoid quadratic allocation
  • 6b02cd3 Fix wrong nextBid computation in IoUringBufferRing for RECVSEND_BUNDLE
  • ef3a3e1 Fix sign-extension bug in SocksInitRequestDecoder NMETHODS field
  • 4cacdf0 Fix quadratic CPU usage in XmlFrameDecoder when an element is never balanced
  • 20f3aae Fail closed on zero-length handshake records in SslClientHelloHandler
  • c3f7088 Netty OcspServerCertificateValidator still delivers buffered data from a revo...
  • 4029f07 Correctly handle multiple Content-Length
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps `netty.version` from 4.2.18.Final to 4.2.19.Final.

Updates `io.netty:netty-codec-http` from 4.2.18.Final to 4.2.19.Final
- [Release notes](https://github.com/netty/netty/releases)
- [Commits](netty/netty@netty-4.2.18.Final...netty-4.2.19.Final)

Updates `io.netty:netty-handler` from 4.2.18.Final to 4.2.19.Final
- [Release notes](https://github.com/netty/netty/releases)
- [Commits](netty/netty@netty-4.2.18.Final...netty-4.2.19.Final)

Updates `io.netty:netty-transport` from 4.2.18.Final to 4.2.19.Final
- [Release notes](https://github.com/netty/netty/releases)
- [Commits](netty/netty@netty-4.2.18.Final...netty-4.2.19.Final)

---
updated-dependencies:
- dependency-name: io.netty:netty-codec-http
  dependency-version: 4.2.19.Final
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: io.netty:netty-handler
  dependency-version: 4.2.19.Final
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: io.netty:netty-transport
  dependency-version: 4.2.19.Final
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot requested a review from a team October 9, 2026 23:27
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Oct 9, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants