Early Access — Mondoo Vulnerability Intelligence is currently in preview.
This update for netty fixes the following issues:
Update to upstream version 4.1.130.
Security issues fixed:
HttpRequestEncoder allows for CRLF injection through a request URI and
can lead to request smuggling (bsc#1255048).Other updates and bugfixes:
Version 4.1.130:
lz4-java version to 1.10.1Channel and fail bootstrap when setting a ChannelOption causes an errorHttpContent for preflight requestNonStickyEventExecutorGroup causing incorrect inEventLoop() resultsZstdEncoder not producing data when source is smaller than blockByteToMessageDecoderMpscIntQueue bugBuild against the org.jboss:jdk-misc artifact that is implementing the sun.misc classes removed in Java 25
4.1.130-150200.4.40.14.1.130-150200.4.40.14.1.130-150200.4.40.14.1.130-150200.4.40.1