-
Notifications
You must be signed in to change notification settings - Fork 99
Closed
Labels
Description
Description
Need to update the netty version to 4.1.118-Final and netty-tcnative version to 2.0.70.Final to address the following security vulnerabilities:
- [High Severity] SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine (CVE-2025-24970)
- [Medium Severity] Denial of Service attack on windows app using Netty (CVE-2025-25193)
Netty release notes - https://netty.io/news/2025/02/10/4-1-118-Final.html
Affected packages:
- tcp
- udp
- http
- grpc
- websocket
Version
Ballerina SwanLake Update 11 - 2201.11.0
Reactions are currently unavailable