Netty 4.2.19.Final released
We are happy to announce the release of Netty 4.2.19.Final. This is a bug-fix and security release.
Note that Netty 4.1 will be End-of-Life on July 1st, 2027.
We strongly recommend upgrading to this version to get the following security fixes:
- CVE-2026-XXXXX : parser desync in
io.netty:netty-codec-haproxy - CVE-2026-XXXXX : improper CRLF neutralization (request/response smuggling) in
io.netty:netty-codec-http - CVE-2026-XXXXX : origin validation error in
io.netty:netty-codec-http - CVE-2026-XXXXX : unbounded resource consumption in
io.netty:netty-codec-http2 - CVE-2026-XXXXX : request/response smuggling in
io.netty:netty-codec-http - CVE-2026-XXXXX : time-of-check/time-of-use error in
io.netty:netty-handler-ssl-ocsp - CVE-2026-XXXXX : SNI routing bypass in
io.netty:netty-handler - CVE-2026-XXXXX : unbounded resource consumption in
io.netty:netty-codec-xml - CVE-2026-XXXXX : unbounded resource consumption in
io.netty:netty-codec-base - CVE-2026-XXXXX : unbounded resource consumption in
io.netty:netty-codec-http - CVE-2026-XXXXX : input misinterpretation in
io.netty:netty-codec-socks - CVE-2026-XXXXX : improper access control in
io.netty:netty-handler - CVE-2026-XXXXX : unbounded resource consumption in
io.netty:netty-codec-dns - CVE-2026-XXXXX : unbounded resource consumption in
io.netty:netty-codec-http3 - CVE-2026-XXXXX : use-after-free in
io.netty:netty-transport-classes-io_uring - CVE-2026-XXXXX : memory leak in
io.netty:netty-transport-native-io_uring
Note that due to overwhelming strain on the CVE infrastructure, we have not gotten a single CVE number assigned to these reports in time for our release. The advisories will be published without.
Specific changes worth calling out:
Validation in FileUpload.setContentType.
Previously, the FileUpload.setContentType methods did not validate their inputs.
They now throw an IllegaalArgumentException if the given string is not formatted as a plausible MIME content type.
Other significant changes are:
- Perf: Use
LinkedHashSetto deduplicate search domains #17400 - Handle non-positive skip lengths in
ByteBufInputStream#17388 - Avoid double promise allocation in
SslHandler.wrap()#17382 HttpUtil.getCharset()must accept whitespace before the nextContent-Typeparameter #17386- codec-dns: Add
SMIMEA,CDS,CDNSKEY,OPENPGPKEY,CSYNC,ZONEMDrecords #17373 - Transport: Avoid
io_uringcompletion callback allocation #17457 - QUIC: Ensure writable events reflect stream capacity #17431
HttpUtil.getMimeType()must not include whitespace before the nextContent-Typeparameter #17456- Fix buffer leak when
recvmmsgreturns singleUDP_GRObatch #17493 - Guard
ChunkedWriteHandler.doFlush()against re-entrant invocation from user code #17438 - Add regression test for
close()cascade reenteringflush()#17497 - Fix
UDP_GROsegment size is lost when reading withrecvmmsg#17492 KQueueDatagramChannel: rewrite IPv4-wildcard bind to IPv6-any on dual-stack sockets #17498- Add option to ignore
MaxDirectMemorySizeJVM argument #17177 - HTTP/2: Remove failed
SETTINGSfromACKqueue #17387 - Make
IoEventLoopGroup.isCompatible/isIoTypeside-effect free #17544 - Reset busy counters after triggering an auto-scale-up decision #17538
ProtobufVarint32FrameDecodermust wait for more data when the length prefix is incomplete #17550QpackEncoder.sectionAcknowledgmentmust not NPE when dynamic table is disabled #17537- Fix missing readable-bytes check in
SmtpResponseDecoder#17516 - Guard against out-of-bounds reads when parsing
ClientHelloSNI extension #17532 - Fix
IndexOutOfBoundsExceptionfrom mismatched varint length inHttp3FrameCodec#17523 - Fix missing readable-bytes checks in
QuicHeaderParser#17515 - Http2: Reserve promised stream before running the request verifier #17495
- Fix HTTP/3 decoding of frames with zero length payloads #17564
- Use random generated
LocalAddressin tests that use local transport #17570 - POOL: Release
ChannelwhenSimpleChannelPoolacquire is cancelled #17569 - Fix missing per-entry clamp in
IoUringBufferRing.useBuffer#17568 - Reject incomplete
PUSH_PROMISErequest headers whenvalidateRequiredPseudoHeadersis enabled #17460 - Add regression tests for
CANCEL_PUSH/GOAWAY/MAX_PUSH_IDtrailing bytes #17571 Http2ConnectionHandler: report at most one stream error for aCompositeStreamException#17470- Restore configurable ioRatio-based task scheduling in
SingleThreadIoEventLoop#17481 - Support creating a
PropertyKeythat is not tied to a specificHttp2Connection#17594 - Reset
LengthFieldBasedFrameDecoderstate when the frame is shorter thaninitialBytesToStrip#17606 SingleThreadEventExecutor: fix race between suspend and cancellation … #17601- Fix
ByteBuf.setBytes(int, ByteBuffer)when the source is the buffer's own internal NIO buffer #17618 - Add missing bounds check to
AdaptiveByteBuf.getBytes(...)channel variants #17620 SingleThreadEventExecutor: fix remaining suspend/cancellation race #17627- Update lz4-java to 1.12.0 #17631
- Fix connection error scope for
SETTINGS_INITIAL_WINDOW_SIZEoverflow issue #17602 - HTTP/2: Fix stream stall when toggling auto-read on a child channel #17617
- Update quiche to a new version 0.30.0 #17642
- No need to call
clear()onByteBufferafterAdaptiveByteBuf.internalNioBuffer()#17619 - Don't strand tasks when
trySuspend()races withstartThread()#17608 PendingWriteQueue: unlink the write before failing it inremoveAndFail#17657- Don't lose
HashedWheelTimertimeouts that race withstop()#17610 - Don't corrupt the pipeline when a handler context is removed twice #17643
LocalChannel: completeconnect()when the accepted channel dies before registration #17656- Don't leak
FixedChannelPoolslots on unrelatedIllegalArgumentException#17609 - Don't leak queued writes in
ChunkedWriteHandleron removal or cancel #17663 - Honour the needle's reader index in
ByteBufUtil.indexOf(ByteBuf, ByteBuf)#17682 - Close idle outbound HTTP/2 child channels when the parent closes #17679
- Only fail in
ZlibDecoderwhen the decompression buffer is full #17692 - Fail pending writes of
ProxyHandlerwhen it is removed #17691 - Arm force-close timeout when an inbound
CLOSEframe is echoed #17574 - Don't count STOMP headers again when the header block is replayed #17664
- Add script that allows to check if a user has signed the ICLA #17711
- Complete HTTP/2 graceful close when the connection closes the last stream #17683
- Handle ed25519 and ed448 names in
SignatureAlgorithmConverter#17689 MqttDecoderaccepts malformed MQTT 5 property sections and reclassifies payload bytes as properties #17714- common: initialize
SystemTickerat runtime in native images #17677 - Don't corrupt
ChannelOutboundBufferwhen a cancelled write makes the channel writable #17702 - Fail
ChunkedNioFileinstead of spinning when the file is shorter than requested #17727 - Validate bzip2 Huffman table selector index before use #17705
- Reset the per-message-deflate compressor after an empty final fragment #17681
- Only build and test the affected modules when validating PRs #17736
- Fix
retainedSlice() of non-retained pooled derived buffers #17759 - Bulk merge changes for 4.2 #17770
For more details please see the complete release notes.
Thank You
Every idea and bug-report counts, and so we thought it is worth mentioning those who helped in this area.
Please report an unintended omission.
- @chrisvest
- @lhotari
- @normanmaurer
- @violetagg
- @doom369
- @yawkat
- @idelpivnitskiy
- @massiccio
- @pandareen
- @octa-one
- @franz1981
- @rajan-github
- @cuishuang
- @skyguard1
- @hyperxpro
- @laosijikaichele
- @hunseonglee
- @fudianchn
- @allthingssecurity
- @eager-signal
- @JunggiKim
- @ohchanKyu
- @renechoi
- @Gimini-3
- @Asthenia0412
- @sanjomo