Skip navigation

Netty 4.1.139.Final released

We are happy to announce the release of Netty 4.1.139.Final. This is a bug-fix and security release.

Note that Netty 4.1 will be End-of-Life on July 1st, 2027.

We strongly recommend upgrading to this version to get the following security fixes:

  • CVE-2026-XXXXX : parser desync in io.netty:netty-codec-haproxy
  • CVE-2026-XXXXX : improper CRLF neutralization (request/response smuggling) in io.netty:netty-codec-http
  • CVE-2026-XXXXX : origin validation error in io.netty:netty-codec-http
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-http2
  • CVE-2026-XXXXX : request/response smuggling in io.netty:netty-codec-http
  • CVE-2026-XXXXX : time-of-check/time-of-use error in io.netty:netty-handler-ssl-ocsp
  • CVE-2026-XXXXX : SNI routing bypass in io.netty:netty-handler
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-xml
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-base
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-http
  • CVE-2026-XXXXX : input misinterpretation in io.netty:netty-codec-socks
  • CVE-2026-XXXXX : improper access control in io.netty:netty-handler
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-dns

Note that due to overwhelming strain on the CVE infrastructure, we have not gotten a single CVE number assigned to these reports in time for our release. The advisories will be published without.

Specific changes worth calling out:

Validation in FileUpload.setContentType. Previously, the FileUpload.setContentType methods did not validate their inputs. They now throw an IllegaalArgumentException if the given string is not formatted as a plausible MIME content type.

Other significant changes are:

  • Perf: Use LinkedHashSet to deduplicate search domains #17407
  • Handle non-positive skip lengths in ByteBufInputStream #17410
  • Protobuf: Update protobuf-javanano to non alpha release #17335
  • HttpUtil.getCharset() must accept whitespace before the next Content-Type parameter #17436
  • Codec-dns: Add SMIMEA, CDS, CDNSKEY, OPENPGPKEY, CSYNC, ZONEMD records #17459
  • HttpUtil.getMimeType() must not include whitespace before the next Content-Type parameter #17494
  • Fix buffer leak when recvmmsg returns single UDP_GRO batch #17500
  • Guard ChunkedWriteHandler.doFlush() against re-entrant invocation from user code #17501
  • Add regression test for close() cascade reentering flush() #17505
  • Fix UDP_GRO segment size is lost when reading with recvmmsg #17506
  • Add workflow that will cancel running workflows for merged PRs #17519
  • HTTP/2: Remove failed SETTINGS from ACK queue #17534
  • ProtobufVarint32FrameDecoder must wait for more data when the length prefix is incomplete #17553
  • Fix missing readable-bytes check in SmtpResponseDecoder #17556
  • Guard against out-of-bounds reads when parsing ClientHello SNI extension #17558
  • Http2: Reserve promised stream before running the request verifier #17563
  • Use random generated LocalAddress in tests that use local transport #17579
  • Use isLengthEqual method in HttpObjectDecoder #17575
  • Reject incomplete PUSH_PROMISE request headers when validateRequiredPseudoHeaders is enabled #17582
  • POOL: Release Channel when SimpleChannelPool acquire is cancelled #17578
  • Http2ConnectionHandler: report at most one stream error for a CompositeStreamException #17595
  • Support creating a PropertyKey that is not tied to a specific Http2Connection #17615
  • Reset LengthFieldBasedFrameDecoder state when the frame is shorter than initialBytesToStrip #17621
  • Fix ByteBuf.setBytes(int, ByteBuffer) when the source is the buffer's own internal NIO buffer #17626
  • Fix connection error scope for SETTINGS_INITIAL_WINDOW_SIZE overflow issue #17640
  • Add missing bounds check to AdaptiveByteBuf.getBytes(...) channel variants #17629
  • Update lz4-java to 1.12.0 #17638
  • HTTP/2: Fix stream stall when toggling auto-read on a child channel #17646
  • No need to call clear() on ByteBuffer after AdaptiveByteBuf.internalNioBuffer() #17653
  • PendingWriteQueue: unlink the write before failing it in removeAndFail #17658
  • Don't lose HashedWheelTimer timeouts that race with stop() #17660
  • LocalChannel: complete connect() when the accepted channel dies before registration #17666
  • Don't leak FixedChannelPool slots on unrelated IllegalArgumentException #17668
  • Don't corrupt the pipeline when a handler context is removed twice #17670
  • Don't leak queued writes in ChunkedWriteHandler on removal or cancel #17676
  • Honour the needle's reader index in ByteBufUtil.indexOf(ByteBuf, ByteBuf) #17687
  • Close idle outbound HTTP/2 child channels when the parent closes #17694
  • Only fail in ZlibDecoder when the decompression buffer is full #17698
  • Add script that allows to check if a user has signed the ICLA #17713
  • Fail pending writes of ProxyHandler when it is removed #17707
  • Complete HTTP/2 graceful close when the connection closes the last stream #17720
  • Don't count STOMP headers again when the header block is replayed #17716
  • Don't corrupt ChannelOutboundBuffer when a cancelled write makes the channel writable #17733
  • Fail ChunkedNioFile instead of spinning when the file is shorter than requested #17734
  • Arm force-close timeout when an inbound CLOSE frame is echoed #17710
  • MqttDecoder accepts malformed MQTT 5 property sections and reclassifies payload bytes as properties #17732
  • Validate bzip2 Huffman table selector index before use #17738
  • Fix retainedSlice() of non-retained pooled derived buffers #17761
  • Reset the per-message-deflate compressor after an empty final fragment #17741
  • Bulk merge changes for 4.1 #17771

For more details please see the complete release notes.

Thank You

Every idea and bug-report counts, and so we thought it is worth mentioning those who helped in this area.

Please report an unintended omission.