HIGHMaven →
Netty affected by MadeYouReset HTTP/2 DDoS vulnerability
Netty affected by MadeYouReset HTTP/2 DDoS vulnerability
Affected packages
- io.grpc:grpc-netty-shaded— before 1.75.0
- io.netty:netty-codec-http2— 4.2.0.Alpha1 → 4.2.4.Final
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/netty/netty/security/advisories/GHSA-prj3-ccx8-p6x4
- https://nvd.nist.gov/vuln/detail/CVE-2025-55163
- https://github.com/grpc/grpc-java/commit/6462ef9a11980e168c21d90bbc7245c728fd1a7a
- https://github.com/netty/netty/commit/be53dc3c9acd9af2e20d0c3c07cd77115a594cf1
- https://github.com/netty/netty
- https://www.kb.cert.org/vuls/id/767506
- http://www.openwall.com/lists/oss-security/2025/08/16/1
Structured record: https://osv.dev/vulnerability/GHSA-prj3-ccx8-p6x4
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta