Package
kafbat-ui-fips
Component
netty-handler
Latest update
7.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
These netty-handler vulnerabilities are fixed only in netty 4.1.135.Final, whose rewritten SslClientHelloHandler ClientHello/SNI decoding regresses the TLS handshake — handshakes for unmapped SNI hostnames are closed before completion, breaking the package's HTTPS endpoint. No higher 4.1.x release is currently available. Remediation is pending an upstream netty release that resolves the SNI handshake regression.
Status