Netty 4.1.139.Final released
We are happy to announce the release of Netty 4.1.139.Final. This is a bug-fix and security release.
Note that Netty 4.1 will be End-of-Life on July 1st, 2027.
We strongly recommend upgrading to this version to get the following security fixes:
- CVE-2026-XXXXX : parser desync in
io.netty:netty-codec-haproxy - CVE-2026-XXXXX : improper CRLF neutralization (request/response smuggling) in
io.netty:netty-codec-http - CVE-2026-XXXXX : origin validation error in
io.netty:netty-codec-http - CVE-2026-XXXXX : unbounded resource consumption in
io.netty:netty-codec-http2 - CVE-2026-XXXXX : request/response smuggling in
io.netty:netty-codec-http - CVE-2026-XXXXX : time-of-check/time-of-use error in
io.netty:netty-handler-ssl-ocsp - CVE-2026-XXXXX : SNI routing bypass in
io.netty:netty-handler - CVE-2026-XXXXX : unbounded resource consumption in
io.netty:netty-codec-xml - CVE-2026-XXXXX : unbounded resource consumption in
io.netty:netty-codec-base - CVE-2026-XXXXX : unbounded resource consumption in
io.netty:netty-codec-http - CVE-2026-XXXXX : input misinterpretation in
io.netty:netty-codec-socks - CVE-2026-XXXXX : improper access control in
io.netty:netty-handler - CVE-2026-XXXXX : unbounded resource consumption in
io.netty:netty-codec-dns
Note that due to overwhelming strain on the CVE infrastructure, we have not gotten a single CVE number assigned to these reports in time for our release. The advisories will be published without.
Specific changes worth calling out:
Validation in FileUpload.setContentType.
Previously, the FileUpload.setContentType methods did not validate their inputs.
They now throw an IllegaalArgumentException if the given string is not formatted as a plausible MIME content type.
Other significant changes are:
- Perf: Use
LinkedHashSetto deduplicate search domains #17407 - Handle non-positive skip lengths in ByteBufInputStream #17410
- Protobuf: Update protobuf-javanano to non alpha release #17335
HttpUtil.getCharset()must accept whitespace before the nextContent-Typeparameter #17436- Codec-dns: Add
SMIMEA,CDS,CDNSKEY,OPENPGPKEY,CSYNC,ZONEMDrecords #17459 HttpUtil.getMimeType()must not include whitespace before the nextContent-Typeparameter #17494- Fix buffer leak when
recvmmsgreturns singleUDP_GRObatch #17500 - Guard
ChunkedWriteHandler.doFlush()against re-entrant invocation from user code #17501 - Add regression test for
close()cascade reenteringflush()#17505 - Fix
UDP_GROsegment size is lost when reading withrecvmmsg#17506 - Add workflow that will cancel running workflows for merged PRs #17519
- HTTP/2: Remove failed
SETTINGSfromACKqueue #17534 ProtobufVarint32FrameDecodermust wait for more data when the length prefix is incomplete #17553- Fix missing readable-bytes check in
SmtpResponseDecoder#17556 - Guard against out-of-bounds reads when parsing
ClientHelloSNI extension #17558 - Http2: Reserve promised stream before running the request verifier #17563
- Use random generated
LocalAddressin tests that use local transport #17579 - Use
isLengthEqualmethod inHttpObjectDecoder#17575 - Reject incomplete
PUSH_PROMISErequest headers whenvalidateRequiredPseudoHeadersis enabled #17582 - POOL: Release
ChannelwhenSimpleChannelPoolacquire is cancelled #17578 Http2ConnectionHandler: report at most one stream error for aCompositeStreamException#17595- Support creating a
PropertyKeythat is not tied to a specificHttp2Connection#17615 - Reset
LengthFieldBasedFrameDecoderstate when the frame is shorter thaninitialBytesToStrip#17621 - Fix
ByteBuf.setBytes(int, ByteBuffer)when the source is the buffer's own internal NIO buffer #17626 - Fix connection error scope for
SETTINGS_INITIAL_WINDOW_SIZEoverflow issue #17640 - Add missing bounds check to
AdaptiveByteBuf.getBytes(...)channel variants #17629 - Update lz4-java to 1.12.0 #17638
- HTTP/2: Fix stream stall when toggling auto-read on a child channel #17646
- No need to call
clear()onByteBufferafterAdaptiveByteBuf.internalNioBuffer()#17653 - PendingWriteQueue: unlink the write before failing it in
removeAndFail#17658 - Don't lose
HashedWheelTimertimeouts that race withstop()#17660 - LocalChannel: complete
connect()when the accepted channel dies before registration #17666 - Don't leak
FixedChannelPoolslots on unrelatedIllegalArgumentException#17668 - Don't corrupt the pipeline when a handler context is removed twice #17670
- Don't leak queued writes in
ChunkedWriteHandleron removal or cancel #17676 - Honour the needle's reader index in
ByteBufUtil.indexOf(ByteBuf, ByteBuf)#17687 - Close idle outbound HTTP/2 child channels when the parent closes #17694
- Only fail in
ZlibDecoderwhen the decompression buffer is full #17698 - Add script that allows to check if a user has signed the ICLA #17713
- Fail pending writes of
ProxyHandlerwhen it is removed #17707 - Complete HTTP/2 graceful close when the connection closes the last stream #17720
- Don't count STOMP headers again when the header block is replayed #17716
- Don't corrupt
ChannelOutboundBufferwhen a cancelled write makes the channel writable #17733 - Fail
ChunkedNioFileinstead of spinning when the file is shorter than requested #17734 - Arm force-close timeout when an inbound
CLOSEframe is echoed #17710 MqttDecoderaccepts malformed MQTT 5 property sections and reclassifies payload bytes as properties #17732- Validate bzip2 Huffman table selector index before use #17738
- Fix
retainedSlice()of non-retained pooled derived buffers #17761 - Reset the per-message-deflate compressor after an empty final fragment #17741
- Bulk merge changes for 4.1 #17771
For more details please see the complete release notes.
Thank You
Every idea and bug-report counts, and so we thought it is worth mentioning those who helped in this area.
Please report an unintended omission.