SSerguey Asael Shinder
Java coding notes: the JVM, and writing software that lasts

Serguey Asael Shinder: Netty 4.2.19 and 4.1.139 fix 16 security advisories, published without CVE numbers

· by Serguey Asael Shinder / Serguey Shinder

Netty released 4.2.19.Final and 4.1.139.Final on 6 October, and the project "strongly recommends" upgrading for the security fixes. The 4.2 release lists 16 advisories; 4.1 lists 13 of them, without the two io_uring issues and the HTTP/3 one.

What they cover, by module, as listed in the release notes:

Each item links to its GitHub security advisory.

Serguey Asael Shinder: Netty 4.2.19 and 4.1.139 fix 16 security advisories, published without CVE numbers
Netty 4.2.19 and 4.1.139 fix 16 security advisories, published without CVE numbers — Serguey Asael Shinder

No CVE numbers. Every entry is written as CVE-2026-XXXXX. The notes explain: "due to overwhelming strain on the CVE infrastructure, we have not gotten a single CVE number assigned to these reports in time for our release. The advisories will be published without." If your dependency scanner matches on CVE IDs, it may not flag these versions as fixing anything until numbers are assigned; the GHSA identifiers in the links are what exists today.

One behaviour change. FileUpload.setContentType previously did not validate its input. It now throws an IllegalArgumentException if the string is not a plausible MIME content type. Code that passed through whatever a client sent will now fail at that call.

Among the other fixes: HttpUtil.getCharset() now accepts whitespace before the next Content-Type parameter and getMimeType() no longer includes it, a buffer leak when recvmmsg returns a single UDP_GRO batch is fixed, and ChunkedWriteHandler.doFlush() is guarded against re-entrant calls from user code.

The notes also repeat that Netty 4.1 reaches end of life on 1 July 2027.