Sploitus

CVE-2025-24970

No indexed exploits for CVE-2025-24970 yet

Netty, an asynchronous, event-driven network application framework, has a vulnerability starting in version 4.1.91.Final and prior to version 4.1.118.Final. When a special crafted packet is received via SslHandler it doesn't correctly handle validation of such a packet in all cases which can lead to a native crash. Version 4.1.118.Final contains a patch. As workaround its possible to either disable the usage of the native SSLEngine or change the code manually.

Netty
< 4.1.118
Fix
Available
CVSS 3.1
7.5 HIGH
EPSS
2.1% (80th percentile)
Weakness
CWE-20
NVD status
Analyzed
Published
2025-02-10
CVE-2025-24970 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2025-24970 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2025-24970 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.