THREAT OPS › Threat News › [GHSA] GHSA-c4c3-7fpv-j4q5 (critical) — Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext
[GHSA] GHSA-c4c3-7fpv-j4q5 (critical) — Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext
GHSA-c4c3-7fpv-j4q5 Severity: critical CVE: CVE-2026-75595
Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext
### Summary A fragmented TLS ClientHello whose handshake header spans multiple records makes Netty silently fall back to the default SslContext; where per-SNI selection is the sole mTLS gate, an unauthenticated attacker can bypass the route's
Indicators of compromise
- CVE-2026-75595cve
Original source: https://github.com/advisories/GHSA-c4c3-7fpv-j4q5