Skip to main content
Components
Vulnerabilities
Pricing
MCP
API
Docs
Sign up
Login
Find vulnerabilities. Fix fast with AI.
Search components by package, version, or CVE to get started.
Get full component data and automated fixes with Sonatype Guide.
Sign up for free
maven
net.bull.javamelody
javamelody-collector-server
2.7.0
javamelody-collector-server 2.7.0
Latest
net.bull.javamelody
Published
Apr 26, 2026
•
Policy
compliance
maven Registry
Developer Trust Score
Recommended Version:
x.y.z
Latest version with 0 known vulnerabilities that meets your policy.
Compare Versions
Overview
Overview
Versions
51
Versions
51
Vulnerabilities
9
Vulnerabilities
9
Dependencies
8
Dependencies
8
Reset filters
Severity
Critical
(0)
High
(0)
Medium
(5)
Low
(0)
CVSS Score
0.0
10.0
EPSS Score
0.0
1.0
Malware
KEV Status
Published
Filter
Sort: Published (Newest first)
5.8
CVE-2026-42581
io.netty:netty-codec-http - Inconsistent Interpretation of HTTP Requests
affected
Severity
Medium
Published
May 7, 2026
6.5
CVE-2026-42580
io.netty:netty-codec-http - Inconsistent Interpretation of HTTP Requests
affected
Severity
Medium
Published
May 7, 2026
6.5
CVE-2026-42585
io.netty:netty-codec-http - Inconsistent Interpretation of HTTP Requests
affected
Severity
Medium
Published
May 7, 2026
5.3
CVE-2026-41417
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`. The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply the same validation. `HttpRequestEncoder` and `RtspEncoder` then write the URI into the request line verbatim. If attacker-controlled input reaches `setUri()`, this enables CRLF injection and insertion of additional HTTP or RTSP requests, leading to HTTP request smuggling or desynchronization on the HTTP side and request injection on the RTSP side. This issue is fixed in versions 4.2.13.Final and 4.1.133.Final.
affected
Severity
Medium
6.5
sonatype-2020-0026
netty-handler - Improper Certificate Validation [ formerly CVE-2023-4586 ]
affected
Severity
Medium
Published
Feb 4, 2020
Published
May 6, 2026