CVE-2026-62380CWE-626

CVE-2026-62380

High · published August 22, 2026

CVSS v3.1
7.5
EPSS
0%
Percentile
16.6
In the wild
Unconfirmed
What it is

Netty (io.netty:netty-codec-socks) versions 4.2.0.Final through 4.2.16.Final and 4.1.x through 4.1.136.Final contain null byte, CRLF, and credential injection vulnerabilities in the SOCKS4 (Socks4ClientEncoder) and SOCKS5 (Socks5ClientEncoder) client encoders, which fail to validate domain address and authentication (username/password) fields. An attacker able to control these fields can inject null bytes or CRLF characters to truncate or alter values, potentially enabling domain spoofing, SOCKS4 userid truncation, authentication data injection, and protocol confusion. Fixed in 4.2.17.Final and 4.1.137.Final.

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS v4.0
6.3 · CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N
EPSS
0.00253 · 16.6th percentile
Weakness
CWE-626 · Null Byte Interaction Error (Poison Null Byte)
Published
2026-08-22T17:16Z
Affected products (2)
ProductVersionsFixed in
netty/netty< 4.1.1374.1.137
netty/netty≥ 4.2.0, < 4.2.174.2.17
References (2)
EPSS history
Timeline
  • 22 AUG 12:26Z
    Netty before 4.2.16.Final SOCKS Proxy Null Byte Injection
    cvelistv5