Serguey Asael Shinder: Micronaut 5.2.15, 4.10.31 and 3.10.15 ship this week's Netty fixes
Micronaut released patch versions on three lines on 7 and 8 October, and the common thread is Netty. The 4.2.19.Final and 4.1.139.Final releases of 6 October carried sixteen advisories published without CVE numbers (covered here on 7 October). A Micronaut application does not pick those up by itself: Micronaut manages its Netty version, so the fix reaches you when the framework moves.
What each line got.
- 5.2.15 (7 October): managed Netty updated to 4.2.19.Final, plus seven bug fixes. The HTTP and WebSocket ones are the relevant part for most services: - HTTP/2: flush the
100 Continuewhen the request body is subscribed after the read; - HTTP/1: fail the response when the connection fails during100 Continuecontent; - WebSocket: decode fragmented messages from the complete payload. - The remaining fixes concern introspection bookkeeping and Micronaut's Python support (async-generator contracts through around-advice, inherited method metadata, nested genericHttpResponsereturn types). - 4.10.31 (8 October): managed Netty to 4.2.19.Final and Jackson to 2.21.7. Nothing else is listed.
- 3.10.15 (8 October): managed Netty to 4.1.139.Final, the fixed version on the older 4.1 line. That is the whole release.

Why the short releases matter most. For 4.10.x and 3.10.x the release notes are one or two dependency lines. That is easy to skim past as housekeeping; here it is the security update. A team on 3.10 — still on Netty 4.1 — gets the 4.1-line fixes without changing frameworks.
What to do. Upgrade within your line: 5.2.14 → 5.2.15, 4.10.30 → 4.10.31, 3.10.14 → 3.10.15. If your build overrides Micronaut's managed Netty version (a BOM override or an explicit io.netty dependency), the framework upgrade will not move it for you — check the resolved version with ./gradlew dependencies or mvn dependency:tree after upgrading, and look for 4.2.19.Final or 4.1.139.Final.
Release contents are quoted from the three GitHub release pages; the Netty advisories themselves are linked from Netty's release notes.