Skip navigation

Netty 4.2.19.Final released

We are happy to announce the release of Netty 4.2.19.Final. This is a bug-fix and security release.

Note that Netty 4.1 will be End-of-Life on July 1st, 2027.

We strongly recommend upgrading to this version to get the following security fixes:

  • CVE-2026-XXXXX : parser desync in io.netty:netty-codec-haproxy
  • CVE-2026-XXXXX : improper CRLF neutralization (request/response smuggling) in io.netty:netty-codec-http
  • CVE-2026-XXXXX : origin validation error in io.netty:netty-codec-http
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-http2
  • CVE-2026-XXXXX : request/response smuggling in io.netty:netty-codec-http
  • CVE-2026-XXXXX : time-of-check/time-of-use error in io.netty:netty-handler-ssl-ocsp
  • CVE-2026-XXXXX : SNI routing bypass in io.netty:netty-handler
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-xml
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-base
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-http
  • CVE-2026-XXXXX : input misinterpretation in io.netty:netty-codec-socks
  • CVE-2026-XXXXX : improper access control in io.netty:netty-handler
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-dns
  • CVE-2026-XXXXX : unbounded resource consumption in io.netty:netty-codec-http3
  • CVE-2026-XXXXX : use-after-free in io.netty:netty-transport-classes-io_uring
  • CVE-2026-XXXXX : memory leak in io.netty:netty-transport-native-io_uring

Note that due to overwhelming strain on the CVE infrastructure, we have not gotten a single CVE number assigned to these reports in time for our release. The advisories will be published without.

Specific changes worth calling out:

Validation in FileUpload.setContentType. Previously, the FileUpload.setContentType methods did not validate their inputs. They now throw an IllegaalArgumentException if the given string is not formatted as a plausible MIME content type.

Other significant changes are:

  • Perf: Use LinkedHashSet to deduplicate search domains #17400
  • Handle non-positive skip lengths in ByteBufInputStream #17388
  • Avoid double promise allocation in SslHandler.wrap() #17382
  • HttpUtil.getCharset() must accept whitespace before the next Content-Type parameter #17386
  • codec-dns: Add SMIMEA, CDS, CDNSKEY, OPENPGPKEY, CSYNC, ZONEMD records #17373
  • Transport: Avoid io_uring completion callback allocation #17457
  • QUIC: Ensure writable events reflect stream capacity #17431
  • HttpUtil.getMimeType() must not include whitespace before the next Content-Type parameter #17456
  • Fix buffer leak when recvmmsg returns single UDP_GRO batch #17493
  • Guard ChunkedWriteHandler.doFlush() against re-entrant invocation from user code #17438
  • Add regression test for close() cascade reentering flush() #17497
  • Fix UDP_GRO segment size is lost when reading with recvmmsg #17492
  • KQueueDatagramChannel: rewrite IPv4-wildcard bind to IPv6-any on dual-stack sockets #17498
  • Add option to ignore MaxDirectMemorySize JVM argument #17177
  • HTTP/2: Remove failed SETTINGS from ACK queue #17387
  • Make IoEventLoopGroup.isCompatible/isIoType side-effect free #17544
  • Reset busy counters after triggering an auto-scale-up decision #17538
  • ProtobufVarint32FrameDecoder must wait for more data when the length prefix is incomplete #17550
  • QpackEncoder.sectionAcknowledgment must not NPE when dynamic table is disabled #17537
  • Fix missing readable-bytes check in SmtpResponseDecoder #17516
  • Guard against out-of-bounds reads when parsing ClientHello SNI extension #17532
  • Fix IndexOutOfBoundsException from mismatched varint length in Http3FrameCodec #17523
  • Fix missing readable-bytes checks in QuicHeaderParser #17515
  • Http2: Reserve promised stream before running the request verifier #17495
  • Fix HTTP/3 decoding of frames with zero length payloads #17564
  • Use random generated LocalAddress in tests that use local transport #17570
  • POOL: Release Channel when SimpleChannelPool acquire is cancelled #17569
  • Fix missing per-entry clamp in IoUringBufferRing.useBuffer #17568
  • Reject incomplete PUSH_PROMISE request headers when validateRequiredPseudoHeaders is enabled #17460
  • Add regression tests for CANCEL_PUSH/GOAWAY/MAX_PUSH_ID trailing bytes #17571
  • Http2ConnectionHandler: report at most one stream error for a CompositeStreamException #17470
  • Restore configurable ioRatio-based task scheduling in SingleThreadIoEventLoop #17481
  • Support creating a PropertyKey that is not tied to a specific Http2Connection #17594
  • Reset LengthFieldBasedFrameDecoder state when the frame is shorter than initialBytesToStrip #17606
  • SingleThreadEventExecutor: fix race between suspend and cancellation … #17601
  • Fix ByteBuf.setBytes(int, ByteBuffer) when the source is the buffer's own internal NIO buffer #17618
  • Add missing bounds check to AdaptiveByteBuf.getBytes(...) channel variants #17620
  • SingleThreadEventExecutor: fix remaining suspend/cancellation race #17627
  • Update lz4-java to 1.12.0 #17631
  • Fix connection error scope for SETTINGS_INITIAL_WINDOW_SIZE overflow issue #17602
  • HTTP/2: Fix stream stall when toggling auto-read on a child channel #17617
  • Update quiche to a new version 0.30.0 #17642
  • No need to call clear() on ByteBuffer after AdaptiveByteBuf.internalNioBuffer() #17619
  • Don't strand tasks when trySuspend() races with startThread() #17608
  • PendingWriteQueue: unlink the write before failing it in removeAndFail #17657
  • Don't lose HashedWheelTimer timeouts that race with stop() #17610
  • Don't corrupt the pipeline when a handler context is removed twice #17643
  • LocalChannel: complete connect() when the accepted channel dies before registration #17656
  • Don't leak FixedChannelPool slots on unrelated IllegalArgumentException #17609
  • Don't leak queued writes in ChunkedWriteHandler on removal or cancel #17663
  • Honour the needle's reader index in ByteBufUtil.indexOf(ByteBuf, ByteBuf) #17682
  • Close idle outbound HTTP/2 child channels when the parent closes #17679
  • Only fail in ZlibDecoder when the decompression buffer is full #17692
  • Fail pending writes of ProxyHandler when it is removed #17691
  • Arm force-close timeout when an inbound CLOSE frame is echoed #17574
  • Don't count STOMP headers again when the header block is replayed #17664
  • Add script that allows to check if a user has signed the ICLA #17711
  • Complete HTTP/2 graceful close when the connection closes the last stream #17683
  • Handle ed25519 and ed448 names in SignatureAlgorithmConverter #17689
  • MqttDecoder accepts malformed MQTT 5 property sections and reclassifies payload bytes as properties #17714
  • common: initialize SystemTicker at runtime in native images #17677
  • Don't corrupt ChannelOutboundBuffer when a cancelled write makes the channel writable #17702
  • Fail ChunkedNioFile instead of spinning when the file is shorter than requested #17727
  • Validate bzip2 Huffman table selector index before use #17705
  • Reset the per-message-deflate compressor after an empty final fragment #17681
  • Only build and test the affected modules when validating PRs #17736
  • Fix retainedSlice() of non-retained pooled derived buffers #17759
  • Bulk merge changes for 4.2 #17770

For more details please see the complete release notes.

Thank You

Every idea and bug-report counts, and so we thought it is worth mentioning those who helped in this area.

Please report an unintended omission.