Repository navigation
fix: bump netty to 4.1.138.Final to remediate CVE-2026-75595 and CVE-2026-75596 - #1097
Conversation
…2026-75596 SslClientHelloHandler#decode checked the wrong offset before reading the handshake header, so a ClientHello split across records could throw and fall back to the default SslContext instead of the SNI-specific one, bypassing per-SNI clientAuth=REQUIRE. The same aggregation path also recopied the whole handshake buffer on every additional record, letting a peer drive quadratic CPU cost with many tiny records. Fixed upstream in 4.1.137.Final; 4.1.138.Final is the newest release on this branch's netty line. Co-Authored-By: Claude Sonnet 5 <[email protected]>
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: QUIET Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe Maven Suggested reviewers: Priority: ⬆️ High Change: Bug fix Merge Risk: ⚪ Minimal · up to This upgrade addresses the stated Netty vulnerabilities without introducing an evidenced regression, so the change is ready to merge. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Code Review by Qodo🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)
Great, no issues found!Qodo reviewed your code and found no material issues that require reviewTip of the day💡 Did you know, you can group findings by type and pick your Finding display, from Minimal to Full Powered by Qodo |
Stage 3 of the CVE-2026-75595/-75596 remediation tracked in scylladb#223. The netty-bom override is a stopgap left from the CVE-2026-59901 cycle, since drifted to 4.2.17.Final. scylladb/java-driver#1097 put netty 4.1.138.Final on scylla-4.x, so once 4.19.2.2 ships the connector can inherit the fix from the driver and the override becomes dead weight. - bump scylladb.version 4.19.2.1 -> 4.19.2.2 - remove the netty.version property - remove the netty-bom import and its stale tracking comment BLOCKED: com.scylladb:java-driver-core:4.19.2.2 is not published yet. Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
Stage 3 of the CVE-2026-75595/-75596 remediation tracked in scylladb#223. The netty-bom override is a stopgap left from the CVE-2026-59901 cycle, since drifted to 4.2.17.Final. scylladb/java-driver#1097 put netty 4.1.138.Final on scylla-4.x, so once 4.19.2.2 ships the connector can inherit the fix from the driver and the override becomes dead weight. - bump scylladb.version 4.19.2.1 -> 4.19.2.2 - remove the netty.version property - remove the netty-bom import and its stale tracking comment BLOCKED: com.scylladb:java-driver-core:4.19.2.2 is not published yet. Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
Stage 3 of the CVE-2026-75595/-75596 remediation tracked in #223. The netty-bom override is a stopgap left from the CVE-2026-59901 cycle, since drifted to 4.2.17.Final. scylladb/java-driver#1097 put netty 4.1.138.Final on scylla-4.x, so once 4.19.2.2 ships the connector can inherit the fix from the driver and the override becomes dead weight. - bump scylladb.version 4.19.2.1 -> 4.19.2.2 - remove the netty.version property - remove the netty-bom import and its stale tracking comment BLOCKED: com.scylladb:java-driver-core:4.19.2.2 is not published yet. Co-authored-by: Claude Opus 5 (1M context) <[email protected]>
A patch-level bump of
netty.versiononscylla-4.x, remediating two CVEs found in aConfluent Hub scan of a downstream consumer (
kafka-connect-scylladbv1.1.8, tracked inscylladb/kafka-connect-scylladb#223).
netty.versionnetty.versionCVE-2026-75595 — SNI/mTLS bypass in
SslClientHelloHandlerSslClientHelloHandler#decodechecks the wrong offset before reading the four-byte TLShandshake header. A ClientHello whose handshake header spans multiple records throws an
IndexOutOfBoundsException, which falls back toselect(ctx, null)— the defaultSslContextinstead of the SNI-specific one. In a deployment relying on per-SNIclientAuth=REQUIREas its sole mTLS gate, the default context's laxer client-auth settinglets an unauthenticated peer bypass that requirement.
CVE-2026-75596 — quadratic CPU cost in the same handshake-aggregation path
The pre-handshake ClientHello aggregation in the same handler recopies the entire buffered
handshake body (
handshakeBuffer.clear()+writeBytes()) on every additional TLS record.An unauthenticated peer can drive quadratic CPU work on the event loop by splitting a large
ClientHello across thousands of tiny records, degrading TLS handling for other clients.
Both fixed upstream in netty 4.1.137.Final / 4.2.17.Final.
4.1.138.Finalis the newestrelease on the 4.1.x line this branch already tracks.
Scope
Root-POM property only (
netty.version) — no source changes.grep -rn 4.1.136.Final --include=pom.xml .finds no other hardcoded copy anywhere in the tree, so every module(
core,core-shaded,integration-tests, etc.) picks up the bump through the property.lz4.versionis untouched — unrelated to this CVE pair.Verification
4.1.138.Finalis published on Maven Central for netty-handler.Leaving the full test matrix to CI — this is a dependency-property bump with no source
changes, same shape as #927 / #990.
Related
renovate/netty-monorepo→4.2.18.Final— that jumps a full major line; this PR takesthe minimal fix on the branch's existing 4.1.x line instead. Safe to leave the dashboard
entry as-is; it'll drop off once this merges.
kafka-connect-scylladbcurrently carries its ownnetty-bomoverridepinned past this fix already (fix(deps): update dependency io.netty:netty-bom to v4.2.17.final kafka-connect-scylladb#206) as a stopgap; once a
release containing this bump ships, that override can be dropped in favor of inheriting
netty from here directly (tracked as Stage 3 in CVE-2026-75595 & CVE-2026-75596: netty-handler SNI/mTLS bypass and handshake DoS kafka-connect-scylladb#223).
🤖 Generated with Claude Code