Repository navigation
[fix][sec] Upgrade Netty to 4.2.18 to address several CVEs and bugs - #26514
Merged
Merged
Conversation
Netty 4.2.18.Final is a bug-fix and security release which resolves 30 advisories across the HTTP, HTTP/2, HTTP/3, STOMP, HAProxy, Memcache, Redis, SMTP and MQTT codecs, plus the OCSP and QUIC handlers. netty-tcnative is bumped 2.0.81.Final -> 2.0.84.Final to stay aligned with what netty-parent:4.2.18.Final declares. Assisted-by: Claude Code (Opus 5)
lhotari
requested review from
Technoboy-,
dao-jun,
david-streamlio,
merlimat and
nodece
September 10, 2026 00:32
2 of 11 tasks
nodece
approved these changes
Sep 10, 2026
dao-jun
added a commit
to ascentstream/pulsar
that referenced
this pull request
Sep 20, 2026
…pache#26514) Port of the upstream netty 4.2.17.Final -> 4.2.18.Final upgrade: - root pom netty.version bump; netty-tcnative follows via the netty-bom (2.0.81.Final -> 2.0.84.Final) - LICENSE.bin.txt (server + shell) netty/tcnative version lines realigned with the bundled jars - ProxyProtocolTest.testSniProxyProtocol: use unresolvable-broker-address in the broker service URL so it matches the certificate SAN, as required by the now default-on hostname verification (same change as upstream PIP-478 core migration apache#26282) Fixes the TLS handshake failures ("Connection already closed") seen with netty 4.2.17 in ProxyServiceTlsStarterTest / ProxyProtocolTest. (cherry picked from commit 7ddeac8e2339f3bd2b9e7c1d3694ec7c1a820bdc)
dao-jun
added a commit
to ascentstream/pulsar
that referenced
this pull request
Sep 20, 2026
…pache#26514) Port of the upstream netty 4.2.17.Final -> 4.2.18.Final upgrade: - root pom netty.version bump; netty-tcnative follows via the netty-bom (2.0.81.Final -> 2.0.84.Final) - LICENSE.bin.txt (server + shell) netty/tcnative version lines realigned with the bundled jars - ProxyProtocolTest.testSniProxyProtocol: use unresolvable-broker-address in the broker service URL so it matches the certificate SAN, as required by the now default-on hostname verification (same change as upstream PIP-478 core migration apache#26282) Fixes the TLS handshake failures ("Connection already closed") seen with netty 4.2.17 in ProxyServiceTlsStarterTest / ProxyProtocolTest. (cherry picked from commit 7ddeac8e2339f3bd2b9e7c1d3694ec7c1a820bdc)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
Netty 4.2.18.Final is a bug-fix and security
release, and upstream "strongly recommends" upgrading.
Security fixes. The release notes list 30 advisories, all shown as
CVE-2026-XXXXX: upstreamstates that "due to overwhelming strain on the CVE infrastructure, we have not gotten a single CVE
number assigned to these reports in time for our release. The advisories will be published without."
At the time of writing none of them have been published yet either — the newest advisory in
netty/netty's GitHub advisory database is still from 2026-08-07 — so there is nothing more specificto link to. By affected artifact:
netty-codec-http(incl. SPDY / RTSP sub-codecs)netty-codec-http3netty-codec-http2netty-codec-http2+netty-codec-http3netty-handler-ssl-ocspnetty-codec-stompnetty-codec-smtpnetty-codec-haproxynetty-codec-memcachenetty-codec-redisnetty-codec-mqttnetty-codec-classes-quicThe categories are unbounded resource usage, denial of service, improper header validation, request
smuggling / parser desync, memory leaks, improper certificate validation and improper CRLF
neutralization.
Two upstream default changes are called out in the release notes. Neither affects Pulsar:
HTTP/2 codec at all — searching all 4619 Java files for
http2/Http2FrameCodec/DefaultHttp2Headers/validateHeadersreturns nothing. The codec is on the classpath onlybecause
async-http-clientdepends on it, and Pulsar's primary HTTPS clients(
PulsarAdmin'sHttpClient,AsyncHttpConnector,FrameworkHttpClientFactory) install a customSslEngineFactorybuilt fromTlsContexts.buildNettyClientContext, which never callsapplicationProtocolConfig, so ALPN never advertisesh2and HTTP/2 is never negotiated. Beyondthat, the newly-default check is the same rule Netty's HTTP/1 path has always enforced —
DefaultHttp2Headers.HTTP2_VALUE_VALIDATORandDefaultHttpHeadersFactory.DEFAULT_VALUE_VALIDATORboth delegate to
HttpHeaderValidationUtil.validateValidHeaderValue— so it is a convergencerather than a new restriction.
X509ExtendedTrustManagerwhen hostname verification is enabled."Pulsar does not use Netty's QUIC support and does not bundle
netty-codec-classes-quic.Non-security fixes. 4.2.18.Final also carries fixes in areas Pulsar exercises:
LastHttpContentinHttpChunkedInput(#17240)AbstractNioChannel.removeReadOp()after concurrent deregistration (#17104)FixedChannelPoolacquire is cancelled (#17287); close active unhealthy channels on release (#17306)codec-dns: fix query OPCODE bit offset and mask (#17314); report and allow setting the full 16-bit EDNS(0) flags field (#17325)JdkZlibDecoder(#17370) andJZlibDecoder(#17392) silently truncating highly compressible streamsBzip2: correctly detect overflow during block size bound check (#17261)VarHandleJCTools queues withoutUnsafe(#17185)netty-tcnative. Bumped 2.0.81.Final → 2.0.84.Final to stay aligned with what
netty-parent:4.2.18.Finalitself declares (<tcnative.version>2.0.84.Final</tcnative.version>).This matters because Pulsar defaults to the native TLS engine —
TlsFactorySupportandClientTlsFactorySupportboth resolve an unsettlsProvidertoSslProvider.OPENSSL_REFCNTwhenever
OpenSsl.isAvailable()— so broker, proxy and client TLS all run through this code bydefault. The 24 commits across those three
releases
contain no BoringSSL change (
boringsslCommitShais byte-identical at0226f30467f540a3f62ef48d453f93927da199b6in both parent POMs) and no public API change(
javap -publicover all ofnetty-tcnative-classesdiffers only in the JPMS module versionstring). What they do contain are JNI/BIO memory-safety fixes on remote-peer-influenced paths:
cast to
size_tfed tomemcpy, i.e. a heap buffer overflowserver_namedecoding allowed an embedded NUL character (NewStringUTF→tcn_new_stringn)BIO_java_bytebufferwrite callback over-reported bytes written, violating theBIO_writecontract*SSLPrivateKeyMethoddid not report signing errors back correctlyDeleteLocalRef(undefined behaviour) that #996 introduced in 2.0.82.Final (#1001) — going straight to 2.0.84.Final skips that windowLD_PRELOAD=/lib/libgcompat.so.0workaround for exactly this class of breakageGiven the recent Conscrypt 2.6.2 glibc-floor incident (#26315), the Linux natives were checked
explicitly: the highest versioned reference is unchanged at
GLIBC_2.12(x86_64) andGLIBC_2.17(aarch64), and the
DT_NEEDEDlist actually shrank —libgcc_s.so.1andld-linux-x86-64.so.2are gone, because the
_Unwind_*family is now statically linked vialibgcc_eh.a. The publishedclassifier set is unchanged, and the macOS
minos(15.0) and Windows import set are unchanged too.Modifications
gradle/libs.versions.toml:netty4.2.17.Final → 4.2.18.Final,netty-tcnative2.0.81.Final → 2.0.84.Finaldistribution/server/src/assemble/LICENSE.bin.txtanddistribution/shell/src/assemble/LICENSE.bin.txtto the new versionsNetty's published module set is unchanged between 4.2.17.Final and 4.2.18.Final, so no
LICENSE.bin.txtline had to be added or removed — only version strings changed.Verifying this change
This change is already covered by existing tests. In addition,
./gradlew checkBinaryLicensewas runlocally for both the server and shell distributions (the shell one with
--rerun) to confirm theLICENSE.bin.txtentries match the jars that are actually bundled, and./gradlew quickCheckpasses.
Does this pull request potentially affect one of the following parts:
If the box was checked, please highlight the changes
Netty is upgraded from 4.2.17.Final to 4.2.18.Final and netty-tcnative from 2.0.81.Final to
2.0.84.Final.