Skip to content

[Aikido] Fix 21 security issues in netty-handler, spring-core, spring-webmvc and 10 more - #369

Open
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/AIK-20596-update-packages-132341386-vjji
Open

aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/AIK-20596-update-packages-132341386-vjji

Conversation

@aikido-autofix

@aikido-autofix aikido-autofix Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Upgrade dependencies to fix critical mTLS bypass via SNI parsing, hostname verification bypass, and open redirect/SSRF vulnerabilities in URL parsing.

⚠️ Breaking changes analysis not available for: io.projectreactor.netty:reactor-netty-http, io.projectreactor:reactor-core, io.projectreactor.netty:reactor-netty-core

✅ No breaking changes for: io.netty:netty-handler, org.springframework:spring-core, org.springframework:spring-webmvc, org.springframework:spring-web, org.springframework:spring-beans, org.springframework:spring-expression, org.springframework:spring-context, io.netty:netty-codec-http2, io.netty:netty-codec-http, io.netty:netty-codec-socks

✅ 21 CVEs resolved by this upgrade, including 1 critical 🚨 CVE

This PR will resolve the following CVEs:

Issue Severity           Description
AIKIDO-2026-445867
🚨 CRITICAL
[netty-handler] TLS ClientHello parsing vulnerability allows attackers to bypass SNI-based SslContext selection, potentially enabling unauthorized access to protected routes in deployments relying solely on SNI for mutual TLS enforcement without additional certificate validation.
AIKIDO-2026-421700
HIGH
[netty-handler] Hostname verification silently fails on Java 25+ due to unavailable Unsafe reflection, allowing clients to accept certificates for wrong hostnames and enabling man-in-the-middle attacks.
CVE-2024-22262
HIGH
[spring-core] UriComponentsBuilder fails to properly parse externally provided URLs, allowing attackers to bypass host validation checks and conduct open redirect or SSRF attacks.
CVE-2024-22243
HIGH
[spring-core] UriComponentsBuilder fails to properly validate URLs parsed from external input, allowing attackers to bypass host validation checks and potentially perform open redirect or SSRF attacks.
CVE-2024-22259
HIGH
[spring-core] UriComponentsBuilder fails to properly parse externally provided URLs, allowing attackers to bypass host validation checks and conduct open redirect or SSRF attacks.
CVE-2024-38809
LOW
[spring-core] ETag parsing from "If-Match" or "If-None-Match" request headers is vulnerable to denial of service attacks through unbounded header processing.
AIKIDO-2026-592216
HIGH
[netty-codec-http2] HTTP/1-to-HTTP/2 conversion incorrectly prioritizes the Host header over request-target authority, allowing attackers to bypass host validation and routing controls through mismatched authority values. This enables host/tenant boundary bypass, cache poisoning, and unintended upstream routing.
AIKIDO-2026-739270
HIGH
[netty-codec-http2] HTTP/2 decompression leaks direct ByteBuf memory when DATA frames are sent on closed decompressor channels, allowing remote attackers to exhaust memory and cause DoS via repeated requests on long-lived connections.
AIKIDO-2026-918525
HIGH
[netty-codec-http2] HTTP/1-to-HTTP/2 conversion improperly handles CONNECT requests, using the Host header instead of the request-target for the :authority pseudo-header, enabling request smuggling and tunnel-destination bypass in proxies.
AIKIDO-2026-58442
HIGH
[netty-codec-http2] HTTP/2 Extended CONNECT requests are improperly downgraded to plain CONNECT tunnels, dropping protocol and path metadata that downstream handlers use for routing and authorization, allowing security policies to be bypassed.
AIKIDO-2026-453463
LOW
[netty-codec-http2] HTTP/2 header values lack validation by default, allowing prohibited octets (NUL, CR, LF) to pass through, enabling request smuggling and response splitting when translated to HTTP/1.1 by proxies or gateways.
AIKIDO-2026-275094
LOW
[netty-codec-http2] Remote clients can send HTTP/2 SETTINGS frames with extremely large header-table sizes, causing the encoder to retain headers indefinitely and degrade to O(n²) lookups, resulting in denial of service through throughput collapse.
AIKIDO-2026-664762
HIGH
[netty-codec-http] Multiple HTTP codec vulnerabilities enable denial-of-service attacks through unbounded queues and memory exhaustion, plus request smuggling via improper chunk-extension and Transfer-Encoding validation. Fixes add bounds checking and stricter validation.
AIKIDO-2026-179204
HIGH
[netty-codec-http] HTTP request/response pairing logic incorrectly matches 1xx interim responses to pipelined requests, causing response bodies to be misrouted and enabling HTTP response splitting and smuggling attacks.
AIKIDO-2026-240696
HIGH
[netty-codec-socks] SOCKS4/5 encoders fail to reject null bytes and CRLF in domain, userid, and credential fields, enabling hostname spoofing, authentication bypass, and connection redirection to unintended targets.
AIKIDO-2026-980617
MEDIUM
[reactor-netty-http] A WebSocket handshake redirect to a different origin can leak credentials when the HTTP client is configured to follow redirects, allowing a remote attacker to intercept credentials meant for the original host.
AIKIDO-2026-718872
MEDIUM
[reactor-netty-http] A vulnerability allows incorrect evaluation of remote IP addresses when HAProxy Protocol is enabled, potentially leading to access-control bypass or incorrect logging based on wrong client identity. This impacts security decisions that rely on the client's IP address.
AIKIDO-2026-556582
LOW
[reactor-netty-http] A remote attacker can cause excessive memory consumption by sending HTTP/1.1 pipelined requests on a single connection, leading to denial of service and reduced server availability. The vulnerability allows degradation or exhaustion of server resources through memory exhaustion.
AIKIDO-2026-268979
MEDIUM
[reactor-core] A 20-bit index wrap in Flux.windowTimeout with fair backpressure can cause the operator to hang indefinitely on long-lived streams, allowing attackers to exhaust resources through denial of service.
AIKIDO-2026-224455
MEDIUM
[reactor-core] A race condition in Flux.bufferTimeout with fair backpressure can cause the stream to hang when upstream items arrive during buffer flushing, leaving items unprocessed. An attacker can exploit this to exhaust subscriptions, resulting in denial of service.
AIKIDO-2026-592409
LOW
[reactor-netty-core] A DNS resolver configuration can be incorrectly reused across multiple dynamically created clients with different resolver settings, causing traffic to be routed to unintended destinations. This allows an attacker to perform DNS hijacking or traffic redirection attacks.
🔗 Related Tasks
🤖 Remediation details

Fix critical and high-severity CVEs in Netty, Spring Framework, and Reactor via direct dependency bumps in agent/build.gradle

Short summary

This PR remediates security vulnerabilities in the following packages: io.netty:netty-handler, io.netty:netty-codec-http2, io.netty:netty-codec-http, io.netty:netty-codec-socks, org.springframework:spring-web, org.springframework:spring-core, org.springframework:spring-beans, io.projectreactor.netty:reactor-netty-http, io.projectreactor.netty:reactor-netty-core, and io.projectreactor:reactor-core. All fixes are applied via two version bumps to direct compileOnly dependencies in agent/build.gradle: io.projectreactor.netty:reactor-netty-http (covers all Netty and Reactor packages) and org.springframework:spring-web (covers all Spring packages).


io.netty:netty-handler

netty-handler is pulled in transitively through io.projectreactor.netty:reactor-netty-http → reactor-netty-core → netty-handler. Bumping the direct compileOnly dependency reactor-netty-http from 1.2.18 to 1.3.7 causes netty-handler to resolve at 4.2.17.Final (previously 4.1.135.Final), which meets the required floor of 4.1.137.Final and addresses the associated heap buffer disclosure and TLS-related vulnerabilities.

io.netty:netty-codec-http2

netty-codec-http2 is a transitive dependency introduced by io.projectreactor.netty:reactor-netty-http. Bumping reactor-netty-http from 1.2.18 to 1.3.7 resolves netty-codec-http2 at 4.2.17.Final (previously 4.1.135.Final), satisfying the required minimum of 4.1.138.Final and remediating multiple HTTP/2 protocol-level vulnerabilities including header handling and flow-control issues.

io.netty:netty-codec-http

netty-codec-http is a transitive dependency introduced by io.projectreactor.netty:reactor-netty-http. The bump of reactor-netty-http from 1.2.18 to 1.3.7 resolves netty-codec-http at 4.2.17.Final (previously 4.1.135.Final), meeting the required floor of 4.1.138.Final and fixing HTTP request/response smuggling vulnerabilities.

io.netty:netty-codec-socks

netty-codec-socks is a transitive dependency introduced via reactor-netty-http → reactor-netty-core → netty-handler-proxy → netty-codec-socks. Bumping reactor-netty-http from 1.2.18 to 1.3.7 resolves netty-codec-socks at 4.2.17.Final (previously 4.1.135.Final), satisfying the required minimum of 4.1.137.Final.

org.springframework:spring-web

spring-web is declared directly as a compileOnly dependency in agent/build.gradle at version 5.3.20. It was bumped in-place to 5.3.38, the smallest 5.3.x release that satisfies all four Spring Framework CVEs (URL parsing and redirect vulnerabilities). This also causes the transitively resolved spring-beans and spring-core to move to 5.3.38.

org.springframework:spring-core

spring-core is resolved transitively via the direct compileOnly dependency org.springframework:spring-web. Bumping spring-web from 5.3.20 to 5.3.38 causes spring-core to resolve at 5.3.38 (previously 5.3.20), meeting the patched version floor for all associated Spring Framework advisories.

org.springframework:spring-beans

spring-beans is resolved transitively via org.springframework:spring-web → spring-beans. Bumping spring-web from 5.3.20 to 5.3.38 causes spring-beans to resolve at 5.3.38 (previously 5.3.20), satisfying the patched version requirement.

io.projectreactor.netty:reactor-netty-http

reactor-netty-http is declared directly as a compileOnly dependency in agent/build.gradle. It was bumped from 1.2.18 to 1.3.7 to remediate vulnerabilities in reactor-netty-http itself and to carry the fixed versions of all dependent Netty and Reactor packages into the resolved dependency graph.

io.projectreactor.netty:reactor-netty-core

reactor-netty-core is a transitive dependency pulled in by io.projectreactor.netty:reactor-netty-http. Bumping reactor-netty-http from 1.2.18 to 1.3.7 resolves reactor-netty-core at 1.3.7 (previously 1.2.18), meeting the required patched version and fixing the associated vulnerability.

io.projectreactor:reactor-core

reactor-core is a transitive dependency introduced by io.projectreactor.netty:reactor-netty-http → reactor-netty-core. Bumping reactor-netty-http from 1.2.18 to 1.3.7 resolves reactor-core at 3.8.7 (previously 3.7.19), satisfying the required minimum of 3.8.7 and addressing the associated reactive-streams vulnerabilities.


Version changes

Package From To Why updated
io.projectreactor.netty:reactor-netty-http 1.2.18 1.3.7 Direct CVE fix; parent bump to carry fixed Netty and Reactor versions
org.springframework:spring-web 5.3.20 5.3.38 Direct CVE fix
io.netty:netty-handler 4.1.135.Final 4.2.17.Final Transitive; resolved after reactor-netty-http bump
io.netty:netty-codec-http2 4.1.135.Final 4.2.17.Final Transitive; resolved after reactor-netty-http bump
io.netty:netty-codec-http 4.1.135.Final 4.2.17.Final Transitive; resolved after reactor-netty-http bump
io.netty:netty-codec-socks 4.1.135.Final 4.2.17.Final Transitive; resolved after reactor-netty-http bump
io.projectreactor.netty:reactor-netty-core 1.2.18 1.3.7 Transitive; resolved after reactor-netty-http bump
io.projectreactor:reactor-core 3.7.19 3.8.7 Transitive; resolved after reactor-netty-http bump
org.springframework:spring-beans 5.3.20 5.3.38 Transitive; resolved after spring-web bump
org.springframework:spring-core 5.3.20 5.3.38 Transitive; resolved after spring-web bump

Comment thread agent/build.gradle

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

2 Open source vulnerabilities detected - high severity
Aikido detected 2 vulnerabilities across 2 packages, it includes 2 high vulnerabilities.

Details

Remediation:

  • netty-codec-classes-quic — 1 CVE (high) — fixed in 4.2.18.Final
  • netty-codec-http3 — 1 CVE (high) — fixed in 4.2.18.Final

Reply @AikidoSec ignore: [REASON] to ignore this issue.
More info

@codecov

codecov Bot commented Oct 3, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants