Vulnerability record · CVE-2025-24970 · published 10 February 2025
CVE-2025-24970: Netty improper input validation vulnerability
Netty · Netty
Netty, an asynchronous, event-driven network application framework, has a vulnerability starting in version 4.1.91.Final and prior to version 4.1.118.Final. When a special crafted packet is received via SslHandler it doesn't correctly handle validation of such a packet in all cases which can lead to a native crash. Version 4.1.118.Final contains a patch. As workaround its possible to either disable the usage of the native SSLEngine or change the code manually.
Description
Netty, an asynchronous, event-driven network application framework, has a vulnerability starting in version 4.1.91.Final and prior to version 4.1.118.Final. When a special crafted packet is received via SslHandler it doesn't correctly handle validation of such a packet in all cases which can lead to a native crash. Version 4.1.118.Final contains a patch. As workaround its possible to either disable the usage of the native SSLEngine or change the code manually.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/netty/netty/commit/87f40725155b2f89adfde68c7732f97c153676c4 | Patch |
| https://github.com/netty/netty/security/advisories/GHSA-4g8c-wm8x-jfhw | Vendor Advisory |
| https://security.netapp.com/advisory/ntap-20250221-0005/ | Third Party Advisory |
| https://www.vicarius.io/vsociety/posts/cve-2025-24970-netty-vulnerability-detection | ExploitThird Party Advisory |
| https://www.vicarius.io/vsociety/posts/cve-2025-24970-netty-vulnerability-mitigation | ExploitMitigationThird Party Advisory |
| https://github.com/netty/netty/security/advisories/GHSA-4g8c-wm8x-jfhw | Vendor Advisory |
Track CVE-2025-24970 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-24970), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.