Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. An unsafe reading of environment file could potentially cause a denial of service in Netty. When loaded on an Windows application, Netty attempts to load a file that does not exist. If an attacker creates such a large file, the Netty application crashes. This vulnerability is fixed in 4.1.115.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/netty/netty/commit/fbf7a704a82e7449b48bd0bbb679f5661c6d61a3 | Patch | 
| https://github.com/netty/netty/security/advisories/GHSA-xq3w-v528-46rv | Exploit Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| AND | 
 
 | 
History
                    05 Sep 2025, 14:00
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://github.com/netty/netty/commit/fbf7a704a82e7449b48bd0bbb679f5661c6d61a3 - Patch | |
| References | () https://github.com/netty/netty/security/advisories/GHSA-xq3w-v528-46rv - Exploit, Vendor Advisory | |
| First Time | Netty Microsoft windows Microsoft Netty netty | |
| CPE | cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* | 
Information
                Published : 2024-11-12 16:15
Updated : 2025-09-05 14:00
NVD link : CVE-2024-47535
Mitre link : CVE-2024-47535
CVE.ORG link : CVE-2024-47535
JSON object : View
Products Affected
                netty
- netty
microsoft
- windows
CWE
                
                    
                        
                        CWE-400
                        
            Uncontrolled Resource Consumption
