[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2022-41881":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T08:55:32.481Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":27,"aliases":37,"duplicate_of":9,"upstream":39,"downstream":40,"duplicates":73,"related":74,"reserved_at":9,"published_at":82,"modified_at":83,"state":84,"summary":85,"references_raw":93,"kevs":131,"epss":132,"epss_history":135,"metrics":407,"affected":421},"CVE-2022-41881","Netty project is an event-driven asynchronous network application framework. In versions prior to 4.1.86.Final, a StackOverflowError can be raised when parsing a malformed crafted message due to an infinite recursion. This issue is patched in version 4.1.86.Final. There is no workaround, except using a custom HaProxyMessageDecoder.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":9,"capec":18},"CWE-674","Uncontrolled Recursion","The product does not properly control the amount of recursion that takes place,  consuming excessive resources, such as allocated memory or the program stack.","weakness","Draft","Class",[19,23],{"id":20,"name":21,"techniques":22},"CAPEC-230","Serialized Data with Nested Payloads",[],{"id":24,"name":25,"techniques":26},"CAPEC-231","Oversized Serialized Data Payloads",[],[28],{"_key":29,"name":30,"source":31,"url":32,"maturity":33,"reliability_score":34,"verified":35,"type":9,"platforms":36,"requires_auth":9,"exploitdb":9,"metasploit":9},"GITHUB_NETTY_NETTY","Netty","github","https://github.com/netty/netty/issues/2562","poc",0.3,false,[],[38],"GHSA-fx2c-96vj-985v",[],[41,43,45,47,49,51,53,55,57,59,61,63,65,67,69,71],{"_key":42},"OPENSUSE-SU-2024:14442-1",{"_key":44},"UBUNTU-CVE-2022-41881",{"_key":46},"SUSE-SU-2023:2096-1",{"_key":48},"SUSE-SU-2023:2096-2",{"_key":50},"DLA-3268-1",{"_key":52},"DSA-5316-1",{"_key":54},"RHSA-2023:2705",{"_key":56},"RHSA-2023:2706",{"_key":58},"RHSA-2023:2707",{"_key":60},"DEBIAN-CVE-2022-41881",{"_key":62},"USN-6049-1",{"_key":64},"RHSA-2025:1746",{"_key":66},"RHSA-2023:1512",{"_key":68},"RHSA-2023:1513",{"_key":70},"RHSA-2023:1514",{"_key":72},"RHSA-2025:1747",[],[75,76,77,78,80],{"_key":42},{"_key":46},{"_key":48},{"_key":79},"CGA-QQ8H-VH95-RJGJ",{"_key":81},"CGA-P5M7-22W8-JHJQ","2022-12-12T00:00:00.000Z","2025-04-22T15:57:46.309Z","Modified",{"cisa_kev":35,"cisa_ransomware":35,"cisa_vendor":9,"epss_severity":86,"epss_score":87,"severity":88,"severity_score":89,"severity_version":90,"severity_source":91,"severity_vector":92,"severity_status":84},"low",0.00448,"high",7.5,"v3.1","nvd","CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",[94,103,108,113,117,122,127],{"url":95,"sources":96,"tags":99},"https://github.com/netty/netty/security/advisories/GHSA-fx2c-96vj-985v",[97,91,98],"cve.org","osv_maven",[100,101,102],"Exploit","Third Party Advisory","WEB",{"url":104,"sources":105,"tags":106},"https://lists.debian.org/debian-lts-announce/2023/01/msg00008.html",[97,91,98],[107,101,102],"Mailing List",{"url":109,"sources":110,"tags":111},"https://www.debian.org/security/2023/dsa-5316",[97,91,98],[112,101,102],"Vendor Advisory",{"url":114,"sources":115,"tags":116},"https://security.netapp.com/advisory/ntap-20230113-0004/",[97,91],[101],{"url":118,"sources":119,"tags":120},"https://nvd.nist.gov/vuln/detail/CVE-2022-41881",[98],[121],"Advisory",{"url":123,"sources":124,"tags":125},"https://github.com/netty/netty",[98],[126],"PACKAGE",{"url":128,"sources":129,"tags":130},"https://security.netapp.com/advisory/ntap-20230113-0004",[98],[102],[],{"date":133,"score":87,"percentile":134},"2026-06-04",0.63861,[136,140,143,146,148,151,154,157,160,163,165,168,171,174,177,181,184,187,190,193,196,199,202,205,208,211,214,217,220,224,227,230,233,236,239,242,245,248,251,254,257,260,263,266,269,272,275,278,281,284,287,290,293,296,299,302,305,309,312,315,318,321,324,327,330,333,336,339,341,344,347,350,353,356,359,362,365,368,371,374,377,380,383,386,389,392,395,398,401,404],{"date":137,"score":138,"percentile":139},"2025-11-04",0.00082,0.24656,{"date":141,"score":138,"percentile":142},"2025-11-05",0.2464,{"date":144,"score":138,"percentile":145},"2025-11-06",0.24647,{"date":147,"score":138,"percentile":139},"2025-11-07",{"date":149,"score":138,"percentile":150},"2025-11-08",0.2466,{"date":152,"score":138,"percentile":153},"2025-11-09",0.24622,{"date":155,"score":138,"percentile":156},"2025-11-10",0.24584,{"date":158,"score":138,"percentile":159},"2025-11-11",0.24589,{"date":161,"score":138,"percentile":162},"2025-11-12",0.24615,{"date":164,"score":138,"percentile":162},"2025-11-13",{"date":166,"score":138,"percentile":167},"2025-11-14",0.24608,{"date":169,"score":138,"percentile":170},"2025-11-15",0.24593,{"date":172,"score":138,"percentile":173},"2025-11-16",0.24548,{"date":175,"score":138,"percentile":176},"2025-11-17",0.24504,{"date":178,"score":179,"percentile":180},"2025-11-18",0.01765,0.81129,{"date":182,"score":179,"percentile":183},"2025-11-19",0.8113,{"date":185,"score":179,"percentile":186},"2025-11-20",0.81133,{"date":188,"score":138,"percentile":189},"2025-11-21",0.24427,{"date":191,"score":138,"percentile":192},"2025-11-22",0.24424,{"date":194,"score":138,"percentile":195},"2025-11-23",0.24373,{"date":197,"score":138,"percentile":198},"2025-11-24",0.24343,{"date":200,"score":138,"percentile":201},"2025-11-25",0.24331,{"date":203,"score":138,"percentile":204},"2025-11-26",0.2432,{"date":206,"score":138,"percentile":207},"2025-11-27",0.24317,{"date":209,"score":138,"percentile":210},"2025-11-28",0.24293,{"date":212,"score":138,"percentile":213},"2025-11-29",0.24277,{"date":215,"score":138,"percentile":216},"2025-11-30",0.24252,{"date":218,"score":138,"percentile":219},"2025-12-01",0.24296,{"date":221,"score":222,"percentile":223},"2025-12-02",0.00102,0.28693,{"date":225,"score":222,"percentile":226},"2025-12-03",0.28701,{"date":228,"score":222,"percentile":229},"2025-12-04",0.28626,{"date":231,"score":222,"percentile":232},"2025-12-05",0.28665,{"date":234,"score":222,"percentile":235},"2025-12-06",0.28664,{"date":237,"score":222,"percentile":238},"2025-12-07",0.28634,{"date":240,"score":222,"percentile":241},"2025-12-08",0.28647,{"date":243,"score":222,"percentile":244},"2025-12-09",0.28704,{"date":246,"score":222,"percentile":247},"2025-12-10",0.28775,{"date":249,"score":222,"percentile":250},"2025-12-11",0.28804,{"date":252,"score":222,"percentile":253},"2025-12-12",0.28824,{"date":255,"score":222,"percentile":256},"2025-12-13",0.28764,{"date":258,"score":222,"percentile":259},"2025-12-14",0.28729,{"date":261,"score":222,"percentile":262},"2025-12-15",0.28696,{"date":264,"score":222,"percentile":265},"2025-12-16",0.28706,{"date":267,"score":222,"percentile":268},"2025-12-17",0.28766,{"date":270,"score":222,"percentile":271},"2025-12-18",0.2882,{"date":273,"score":222,"percentile":274},"2025-12-19",0.28833,{"date":276,"score":222,"percentile":277},"2025-12-20",0.28798,{"date":279,"score":222,"percentile":280},"2025-12-21",0.28751,{"date":282,"score":222,"percentile":283},"2025-12-22",0.28714,{"date":285,"score":222,"percentile":286},"2025-12-23",0.28686,{"date":288,"score":222,"percentile":289},"2025-12-24",0.28695,{"date":291,"score":222,"percentile":292},"2025-12-25",0.28768,{"date":294,"score":222,"percentile":295},"2025-12-26",0.2876,{"date":297,"score":222,"percentile":298},"2025-12-27",0.28754,{"date":300,"score":222,"percentile":301},"2025-12-28",0.28674,{"date":303,"score":222,"percentile":304},"2025-12-29",0.28645,{"date":306,"score":307,"percentile":308},"2025-12-30",0.00118,0.31408,{"date":310,"score":307,"percentile":311},"2025-12-31",0.31458,{"date":313,"score":307,"percentile":314},"2026-01-01",0.31597,{"date":316,"score":307,"percentile":317},"2026-01-02",0.31582,{"date":319,"score":307,"percentile":320},"2026-01-03",0.31565,{"date":322,"score":307,"percentile":323},"2026-01-04",0.31428,{"date":325,"score":307,"percentile":326},"2026-01-05",0.31418,{"date":328,"score":307,"percentile":329},"2026-01-06",0.31432,{"date":331,"score":307,"percentile":332},"2026-01-07",0.31454,{"date":334,"score":307,"percentile":335},"2026-01-08",0.31482,{"date":337,"score":307,"percentile":338},"2026-01-09",0.31477,{"date":340,"score":307,"percentile":338},"2026-01-10",{"date":342,"score":307,"percentile":343},"2026-01-11",0.31443,{"date":345,"score":307,"percentile":346},"2026-01-12",0.31382,{"date":348,"score":307,"percentile":349},"2026-01-13",0.3136,{"date":351,"score":307,"percentile":352},"2026-01-14",0.31403,{"date":354,"score":307,"percentile":355},"2026-01-15",0.314,{"date":357,"score":307,"percentile":358},"2026-01-16",0.31425,{"date":360,"score":307,"percentile":361},"2026-01-17",0.31422,{"date":363,"score":307,"percentile":364},"2026-01-18",0.31366,{"date":366,"score":307,"percentile":367},"2026-01-19",0.31334,{"date":369,"score":307,"percentile":370},"2026-01-20",0.31319,{"date":372,"score":307,"percentile":373},"2026-01-21",0.31263,{"date":375,"score":307,"percentile":376},"2026-01-22",0.3124,{"date":378,"score":307,"percentile":379},"2026-01-23",0.31307,{"date":381,"score":307,"percentile":382},"2026-01-24",0.31323,{"date":384,"score":307,"percentile":385},"2026-01-25",0.31251,{"date":387,"score":307,"percentile":388},"2026-01-26",0.31172,{"date":390,"score":307,"percentile":391},"2026-01-27",0.31161,{"date":393,"score":307,"percentile":394},"2026-01-28",0.31137,{"date":396,"score":307,"percentile":397},"2026-01-29",0.31093,{"date":399,"score":307,"percentile":400},"2026-01-30",0.3108,{"date":402,"score":307,"percentile":403},"2026-01-31",0.31086,{"date":405,"score":307,"percentile":406},"2026-02-01",0.31167,[408,415,419],{"source":97,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":409,"cvss_v4_0":9},{"baseScore":410,"baseSeverity":411,"vectorString":412,"impactScore":413,"exploitabilityScore":414},5.3,"MEDIUM","CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",2.3,10,{"source":91,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":416,"cvss_v4_0":9},{"baseScore":89,"baseSeverity":417,"vectorString":92,"impactScore":418,"exploitabilityScore":414},"HIGH",6,{"source":98,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":420,"cvss_v4_0":9},{"baseScore":410,"baseSeverity":9,"vectorString":412,"impactScore":413,"exploitabilityScore":414},[422,433,446],{"ecosystem":9,"name":423,"vendor":424,"product":425,"cpe_part":426,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":427},"debian linux","debian","debian_linux","o",[428,431],{"version":429,"is_range":35,"range_type":430,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"10.0","cpe",{"version":432,"is_range":35,"range_type":430,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0",{"ecosystem":434,"name":435,"vendor":436,"product":437,"cpe_part":9,"purl_type":438,"purl_namespace":436,"purl_name":437,"source":9,"versions":439},"Maven","io.netty:netty-codec-haproxy","io.netty","netty-codec-haproxy","maven",[440],{"version":441,"is_range":442,"range_type":443,"version_start":9,"version_start_type":9,"version_end":444,"version_end_type":445,"fixed_in":9},"lt4_1_86_Final",true,"ecosystem","4.1.86.Final","excluding",{"ecosystem":9,"name":447,"vendor":447,"product":447,"cpe_part":448,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":449},"netty","a",[450,452],{"version":451,"is_range":442,"range_type":97,"version_start":9,"version_start_type":9,"version_end":444,"version_end_type":445,"fixed_in":9},"\u003C 4.1.86.Final",{"version":453,"is_range":442,"range_type":430,"version_start":9,"version_start_type":9,"version_end":454,"version_end_type":445,"fixed_in":9},"lt4.1.86","4.1.86"]