{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/netty-handler-vulnerable--4.1.136.final/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-75595"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["netty-handler (vulnerable: \u003e= 4.2.0.Final, \u003c= 4.2.16.Final)","netty-handler (vulnerable: \u003c= 4.1.136.Final)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Netty"],"content_html":"\u003cp\u003eThe Netty framework contains a vulnerability (CVE-2026-75595) in \u003ccode\u003eio.netty.handler.ssl.SslClientHelloHandler\u003c/code\u003e where the parser incorrectly validates the TLS ClientHello handshake header. Specifically, the implementation fails to account for the 5-byte TLS record header when calculating the offset for the handshake length. If a client sends a fragmented TLS ClientHello such that the first record's payload is less than 4 bytes, the parser encounters an IndexOutOfBoundsException. This exception is caught by a generic handler that silently falls back to the default \u003ccode\u003eSslContext\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eThis flaw becomes a critical security risk when mTLS is enforced exclusively through per-SNI \u003ccode\u003eSslContext\u003c/code\u003e selection. If an organization relies on SNI-based routing to apply mTLS requirements (clientAuth=REQUIRE) but maintains a permissive default \u003ccode\u003eSslContext\u003c/code\u003e (clientAuth=NONE or OPTIONAL) for fallback, an unauthenticated attacker can bypass the intended mTLS protection by intentionally fragmenting the initial TLS handshake to trigger the fallback logic.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated attacker to bypass mTLS authentication controls on affected systems. This impacts any environment relying on per-SNI \u003ccode\u003eSslContext\u003c/code\u003e selection as the primary mechanism for mTLS enforcement without secondary application-layer peer-certificate validation. Depending on the backend application, this could lead to unauthorized access to internal services or API endpoints that expect authenticated client traffic.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the upgrade of all applications using the \u003ccode\u003enetty-handler\u003c/code\u003e library to patched versions. As this is a library-level vulnerability, detection engineering should focus on application-layer logging and monitoring of TLS connection configurations.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade \u003ccode\u003eio.netty:netty-handler\u003c/code\u003e to version 4.1.137.Final or 4.2.17.Final or later, as provided by the vendor.\u003c/li\u003e\n\u003cli\u003eReview server-side TLS configurations to ensure that the default \u003ccode\u003eSslContext\u003c/code\u003e is not configured with permissive client authentication (clientAuth=NONE) if the application handles sensitive routes.\u003c/li\u003e\n\u003cli\u003eImplement application-layer peer-certificate validation to ensure that mTLS requirements are enforced regardless of the initial TLS routing context.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-08T20:04:42Z","date_published":"2026-09-08T20:04:42Z","id":"https://feed.craftedsignal.io/briefs/2026-09-netty-sni-bypass/","summary":"A vulnerability in the Netty TLS ClientHello parsing logic allows unauthenticated attackers to bypass SNI-based mTLS requirements by sending fragmented handshake data that triggers a fallback to a permissive default SSL context.","title":"Netty SNI Routing and mTLS Bypass Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-09-netty-sni-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Netty-Handler (Vulnerable: \u003c= 4.1.136.Final)","version":"https://jsonfeed.org/version/1.1"}