Skip to content

Vulnerabiltiy CVE-2025-24970 in Netty library #6098

Closed
@nr-ashishkumar

Description

@nr-ashishkumar

Describe the bug

software.amazon.awssdk:netty-nio-client:latest library includes 4.1.118.Final version of transitive Netty dependencies.
4.1.118.Final version has vulnerability CVE-2025-24970 and its fix is available in the newer version of transitive dependencies 4.1.119.Final but its not yet adapted by software.amazon.awssdk:netty-nio-client:latest library pom.xml

Vulnerability fixing PR (Merged on 14-Feb-25): Replace SSL assertion with explicit record length check (#14810) by chrisvest · Pull Request #14822 · netty/netty

Regression Issue

  • Select this option if this issue appears to be a regression.

Expected Behavior

No change in the behavior. CVE-2025-24970 vulnerability must be fixed.

Current Behavior

NA

Reproduction Steps

NA

Possible Solution

#6097

Additional Information/Context

No response

AWS Java SDK version used

2.30.23

JDK version used

11

Operating System and version

linux arm64 22.04

Metadata

Metadata

Assignees

Labels

bugThis issue is a bug.p2This is a standard priority issueresponse-requestedWaiting on additional info and feedback. Will move to "closing-soon" in 10 days.

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions