Skip to content

Address Netty Security Vulnerabilities #7571

@TharmiganK

Description

@TharmiganK

Description

Need to update the netty version to 4.1.118-Final and netty-tcnative version to 2.0.70.Final to address the following security vulnerabilities:

  • [High Severity] SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine (CVE-2025-24970)
  • [Medium Severity] Denial of Service attack on windows app using Netty (CVE-2025-25193)

Netty release notes - https://netty.io/news/2025/02/10/4-1-118-Final.html

Affected packages:

  • tcp
  • udp
  • http
  • grpc
  • websocket

Version

Ballerina SwanLake Update 11 - 2201.11.0

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions