THREAT OPS › Threat News › [NVD] CVE-2026-62243 (HIGH 7.5) — Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final and versions through 4.1.136.Final disable TLS hostname verification on the SslProvider.OPENSSL client path when a plain (non-extended) X509TrustManager is used and Unsafe-based trust-manager wrapping i
[NVD] CVE-2026-62243 (HIGH 7.5) — Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final and versions through 4.1.136.Final disable TLS hostname verification on the SslProvider.OPENSSL client path when a plain (non-extended) X509TrustManager is used and Unsafe-based trust-manager wrapping i
CVE-2026-62243 CVSS: 7.5 HIGH Published: 2026-08-22T13:16:39.687
Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final and versions through 4.1.136.Final disable TLS hostname verification on the SslProvider.OPENSSL client path when a plain (non-extended) X509TrustManager is used and Unsafe-based trust-manager wrapping is unavailable (Java 25+). In this configuration the Op
Indicators of compromise
- CVE-2026-62243cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-62243