Skip to content

fix: bump netty to 4.1.138.Final to remediate CVE-2026-75595 and CVE-2026-75596 - #1097

Merged
dkropachev merged 1 commit into
scylladb:scylla-4.xfrom
nikagra:fix/cve-2026-75595-75596-bump-netty-4x
Sep 16, 2026
Merged

dkropachev merged 1 commit into
scylladb:scylla-4.xfrom
nikagra:fix/cve-2026-75595-75596-bump-netty-4x

Conversation

@nikagra

@nikagra nikagra commented Sep 16, 2026 •

Copy link
Copy Markdown

A patch-level bump of netty.version on scylla-4.x, remediating two CVEs found in a
Confluent Hub scan of a downstream consumer (kafka-connect-scylladb v1.1.8, tracked in
scylladb/kafka-connect-scylladb#223).

CVE Property Before After Severity
CVE-2026-75595 netty.version 4.1.136.Final 4.1.138.Final CRITICAL
CVE-2026-75596 netty.version 4.1.136.Final 4.1.138.Final MEDIUM

CVE-2026-75595 — SNI/mTLS bypass in SslClientHelloHandler

SslClientHelloHandler#decode checks the wrong offset before reading the four-byte TLS
handshake header. A ClientHello whose handshake header spans multiple records throws an
IndexOutOfBoundsException, which falls back to select(ctx, null) — the default
SslContext instead of the SNI-specific one. In a deployment relying on per-SNI
clientAuth=REQUIRE as its sole mTLS gate, the default context's laxer client-auth setting
lets an unauthenticated peer bypass that requirement.

CVE-2026-75596 — quadratic CPU cost in the same handshake-aggregation path

The pre-handshake ClientHello aggregation in the same handler recopies the entire buffered
handshake body (handshakeBuffer.clear() + writeBytes()) on every additional TLS record.
An unauthenticated peer can drive quadratic CPU work on the event loop by splitting a large
ClientHello across thousands of tiny records, degrading TLS handling for other clients.

Both fixed upstream in netty 4.1.137.Final / 4.2.17.Final. 4.1.138.Final is the newest
release on the 4.1.x line this branch already tracks.

Scope

Root-POM property only (netty.version) — no source changes. grep -rn 4.1.136.Final --include=pom.xml . finds no other hardcoded copy anywhere in the tree, so every module
(core, core-shaded, integration-tests, etc.) picks up the bump through the property.
lz4.version is untouched — unrelated to this CVE pair.

Verification

4.1.138.Final is published on Maven Central for netty-handler.

$ mvn -pl core -am dependency:list -Dincludes=io.netty:netty-handler
[INFO]    io.netty:netty-handler:jar:4.1.138.Final:compile -- module io.netty.handler
[INFO] BUILD SUCCESS

Leaving the full test matrix to CI — this is a dependency-property bump with no source
changes, same shape as #927 / #990.

Related

🤖 Generated with Claude Code

…2026-75596

SslClientHelloHandler#decode checked the wrong offset before reading
the handshake header, so a ClientHello split across records could
throw and fall back to the default SslContext instead of the
SNI-specific one, bypassing per-SNI clientAuth=REQUIRE. The same
aggregation path also recopied the whole handshake buffer on every
additional record, letting a peer drive quadratic CPU cost with many
tiny records. Fixed upstream in 4.1.137.Final; 4.1.138.Final is the
newest release on this branch's netty line.

Co-Authored-By: Claude Sonnet 5 <[email protected]>
@coderabbitai

coderabbitai Bot commented Sep 16, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: QUIET

Plan: Advanced

Run ID: eb7b4d7d-4ced-4c9d-99a3-6ad287f2dc7c

📥 Commits

Reviewing files that changed from the base of the PR and between 05d6f14 and 8368772.

📒 Files selected for processing (1)
  • pom.xml

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The Maven netty.version property changes from 4.1.136.Final to 4.1.138.Final.

Suggested reviewers: dkropachev

Priority: ⬆️ High

Change: Bug fix

Merge Risk: ⚪ Minimal · up to 83687

This upgrade addresses the stated Netty vulnerabilities without introducing an evidenced regression, so the change is ready to merge.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly identifies the Netty version bump and its security purpose.
Description check ✅ Passed The description directly explains the dependency update, affected CVEs, scope, and verification.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@qodo-scylladb

qodo-scylladb Bot commented Sep 16, 2026

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)

Great, no issues found!

Qodo reviewed your code and found no material issues that require review
Tip of the day
💡 Did you know, you can group findings by type and pick your Finding display, from Minimal to Full

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗


Powered by Qodo

@dkropachev
dkropachev merged commit d954342 into scylladb:scylla-4.x Sep 16, 2026
27 checks passed
nikagra added a commit to nikagra/kafka-connect-scylladb that referenced this pull request Oct 1, 2026
Stage 3 of the CVE-2026-75595/-75596 remediation tracked in scylladb#223.

The netty-bom override is a stopgap left from the CVE-2026-59901 cycle,
since drifted to 4.2.17.Final. scylladb/java-driver#1097 put netty
4.1.138.Final on scylla-4.x, so once 4.19.2.2 ships the connector can
inherit the fix from the driver and the override becomes dead weight.

- bump scylladb.version 4.19.2.1 -> 4.19.2.2
- remove the netty.version property
- remove the netty-bom import and its stale tracking comment

BLOCKED: com.scylladb:java-driver-core:4.19.2.2 is not published yet.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
nikagra added a commit to nikagra/kafka-connect-scylladb that referenced this pull request Oct 2, 2026
Stage 3 of the CVE-2026-75595/-75596 remediation tracked in scylladb#223.

The netty-bom override is a stopgap left from the CVE-2026-59901 cycle,
since drifted to 4.2.17.Final. scylladb/java-driver#1097 put netty
4.1.138.Final on scylla-4.x, so once 4.19.2.2 ships the connector can
inherit the fix from the driver and the override becomes dead weight.

- bump scylladb.version 4.19.2.1 -> 4.19.2.2
- remove the netty.version property
- remove the netty-bom import and its stale tracking comment

BLOCKED: com.scylladb:java-driver-core:4.19.2.2 is not published yet.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
dkropachev pushed a commit to scylladb/kafka-connect-scylladb that referenced this pull request Oct 2, 2026
Stage 3 of the CVE-2026-75595/-75596 remediation tracked in #223.

The netty-bom override is a stopgap left from the CVE-2026-59901 cycle,
since drifted to 4.2.17.Final. scylladb/java-driver#1097 put netty
4.1.138.Final on scylla-4.x, so once 4.19.2.2 ships the connector can
inherit the fix from the driver and the override becomes dead weight.

- bump scylladb.version 4.19.2.1 -> 4.19.2.2
- remove the netty.version property
- remove the netty-bom import and its stale tracking comment

BLOCKED: com.scylladb:java-driver-core:4.19.2.2 is not published yet.

Co-authored-by: Claude Opus 5 (1M context) <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants