CVE-2025-59419
published 2025-10-15CVE-2025-59419: Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.128.Final and 4.2.7.Final, the SMTP codec in Netty contains an…
PriorityP343medium5.5CVSS 4.0
AVNACLATNPRNUINVCNVILVANSCNSINSANEPCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
1.59%
73.0th percentile
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.128.Final and 4.2.7.Final, the SMTP codec in Netty contains an SMTP command injection vulnerability due to insufficient input validation for Carriage Return (\r) and Line Feed (\n) characters in user-supplied parameters. The vulnerability exists in io.netty.handler.codec.smtp.DefaultSmtpRequest, where parameters are directly concatenated into the SMTP command string without sanitization. When methods such as SmtpRequests.rcpt(recipient) are called with a malicious string containing CRLF sequences, attackers can inject arbitrary SMTP commands. Because the injected commands are sent from the server's trusted IP address, resulting emails will likely pass SPF and DKIM authentication checks, making them appear legitimate. This allows remote attackers who can control SMTP command parameters (such as email recipients) to forge arbitrary emails from the trusted server, potentially impersonating executives and forging high-stakes corporate communications. This issue has been patched in versions 4.1.129.Final and 4.2.8.Final. No known workarounds exist.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | netty | < netty 1:4.1.48-7+deb12u2 (bookworm) | netty 1:4.1.48-7+deb12u2 (bookworm) |
| netty | netty | < 4.2.7.Final | 4.2.7.Final |
| netty | netty | — | — |
| netty | netty | >= 0 < 1:4.1.48-4+deb11u3 | 1:4.1.48-4+deb11u3 |
| netty | netty | >= 0 < 1:4.1.48-7+deb12u2 | 1:4.1.48-7+deb12u2 |
| netty | netty | >= 0 < 1:4.1.48-10+deb13u1 | 1:4.1.48-10+deb13u1 |
| netty | netty | >= 0 < 1:4.1.48-11 | 1:4.1.48-11 |
CVSS provenance
nvdv4.05.5MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv5.5MEDIUM
vendor_oracle6.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle GoldenGate Risk Matrix: Java Delivery (Netty) — CVE-2025-59419
vendor_oracle·2026-01-15·CVSS 6.5
CVE-2025-59419 [MEDIUM] Oracle Oracle GoldenGate Risk Matrix: Java Delivery (Netty) — CVE-2025-59419
Oracle Oracle GoldenGate Risk Matrix: Java Delivery (Netty) vulnerability
CVE: CVE-2025-59419
CVSS: 6.5
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujan2026 (JAN 2026)
Ubuntu
Netty vulnerability
vendor_ubuntu·2025-10-28
CVE-2025-59419 Netty vulnerability
Title: Netty vulnerability
Summary: Netty could be made to send emails as your login if it received specially
crafted input.
It was discovered that Netty did not properly handle user input. A remote
attacker could possibly use this issue to forge arbitrary emails from a
trusted server.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
io.netty/netty-codec-smtp: Netty netty-codec-smtp SMTP Command Injection
vendor_redhat·2025-10-15·CVSS 5.5
CVE-2025-59419 [MEDIUM] CWE-93 io.netty/netty-codec-smtp: Netty netty-codec-smtp SMTP Command Injection
io.netty/netty-codec-smtp: Netty netty-codec-smtp SMTP Command Injection
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.128.Final and 4.2.7.Final, the SMTP codec in Netty contains an SMTP command injection vulnerability due to insufficient input validation for Carriage Return (\r) and Line Feed (\n) characters in user-supplied parameters. The vulnerability exists in io.netty.handler.codec.smtp.DefaultSmtpRequest, where parameters are directly concatenated into the SMTP command string without sanitization. When methods such as SmtpRequests.rcpt(recipient) are called with a malicious string containing CRLF sequences, attackers can inject arbitrary SMTP commands. Because the injected commands are sent from the server's trusted IP address, resul
Debian
CVE-2025-59419: netty - Netty is an asynchronous, event-driven network application framework. In version...
vendor_debian·2025·CVSS 5.5
CVE-2025-59419 [MEDIUM] CVE-2025-59419: netty - Netty is an asynchronous, event-driven network application framework. In version...
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.128.Final and 4.2.7.Final, the SMTP codec in Netty contains an SMTP command injection vulnerability due to insufficient input validation for Carriage Return (\r) and Line Feed (\n) characters in user-supplied parameters. The vulnerability exists in io.netty.handler.codec.smtp.DefaultSmtpRequest, where parameters are directly concatenated into the SMTP command string without sanitization. When methods such as SmtpRequests.rcpt(recipient) are called with a malicious string containing CRLF sequences, attackers can inject arbitrary SMTP commands. Because the injected commands are sent from the server's trusted IP address, resulting emails will likely pass SPF and DKIM authentication checks, making th
OSV
CVE-2025-59419: Netty is an asynchronous, event-driven network application framework
osv·2025-10-15·CVSS 5.5
CVE-2025-59419 [MEDIUM] CVE-2025-59419: Netty is an asynchronous, event-driven network application framework
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.128.Final and 4.2.7.Final, the SMTP codec in Netty contains an SMTP command injection vulnerability due to insufficient input validation for Carriage Return (\r) and Line Feed (\n) characters in user-supplied parameters. The vulnerability exists in io.netty.handler.codec.smtp.DefaultSmtpRequest, where parameters are directly concatenated into the SMTP command string without sanitization. When methods such as SmtpRequests.rcpt(recipient) are called with a malicious string containing CRLF sequences, attackers can inject arbitrary SMTP commands. Because the injected commands are sent from the server's trusted IP address, resulting emails will likely pass SPF and DKIM authentication checks, making th
GHSA
Netty has SMTP Command Injection Vulnerability that Allows Email Forgery
ghsa·2025-10-15
CVE-2025-59419 [HIGH] CWE-78 Netty has SMTP Command Injection Vulnerability that Allows Email Forgery
Netty has SMTP Command Injection Vulnerability that Allows Email Forgery
### Summary
An SMTP Command Injection (CRLF Injection) vulnerability in Netty's SMTP codec allows a remote attacker who can control SMTP command parameters (e.g., an email recipient) to forge arbitrary emails from the trusted server. This bypasses standard email authentication and can be used to impersonate executives and forge high-stakes corporate communications.
### Details
The root cause is the lack of input validation for Carriage Return (\r) and Line Feed (\n) characters in user-supplied parameters.
The vulnerable code is in io.netty.handler.codec.smtp.DefaultSmtpRequest, where parameters are directly concatenated into the SMTP command string. For example, when SmtpRequests.rcpt(recipient) is called, a malici
OSV
Netty has SMTP Command Injection Vulnerability that Allows Email Forgery
osv·2025-10-15
CVE-2025-59419 [HIGH] Netty has SMTP Command Injection Vulnerability that Allows Email Forgery
Netty has SMTP Command Injection Vulnerability that Allows Email Forgery
### Summary
An SMTP Command Injection (CRLF Injection) vulnerability in Netty's SMTP codec allows a remote attacker who can control SMTP command parameters (e.g., an email recipient) to forge arbitrary emails from the trusted server. This bypasses standard email authentication and can be used to impersonate executives and forge high-stakes corporate communications.
### Details
The root cause is the lack of input validation for Carriage Return (\r) and Line Feed (\n) characters in user-supplied parameters.
The vulnerable code is in io.netty.handler.codec.smtp.DefaultSmtpRequest, where parameters are directly concatenated into the SMTP command string. For example, when SmtpRequests.rcpt(recipient) is called, a malici
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-10-15
Published