PT-2025-42370 · Netty+5 · Netty+5

Published

2025-10-15

·

Updated

2026-05-18

·

CVE-2025-59419

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Netty versions prior to 4.1.128.Final and 4.2.7.Final
Description Netty contains an SMTP command injection vulnerability due to insufficient input validation for Carriage Return (r) and Line Feed ( ) characters in user-supplied parameters. The vulnerability exists in io.netty.handler.codec.smtp.DefaultSmtpRequest, where parameters are directly concatenated into the SMTP command string without sanitization. When methods such as SmtpRequests.rcpt(recipient) are called with a malicious string containing CRLF sequences, attackers can inject arbitrary SMTP commands. Because the injected commands are sent from the server’s trusted IP address, resulting emails will likely pass SPF and DKIM authentication checks, allowing attackers to forge emails from the trusted server. This could lead to economic manipulation, disinformation, and sophisticated phishing attacks. A proof-of-concept (PoC) is available demonstrating the vulnerability against a local SMTP server.
Recommendations Upgrade to Netty version 4.1.128.Final or 4.2.7.Final or later.

Exploit

Fix

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-14439
CLEANSTART-2026-DD05788
CLEANSTART-2026-JU62349
CLEANSTART-2026-KU61465
CLEANSTART-2026-LE11246
CLEANSTART-2026-RN56220
CLEANSTART-2026-SQ91016
CLEANSTART-2026-SV95049
CLEANSTART-2026-VH41554
CLEANSTART-2026-WK99982
CVE-2025-59419
GHSA-JQ43-27X9-3V86
OESA-2025-2526
OESA-2025-2527
OESA-2025-2528
OESA-2025-2529
OESA-2025-2530
OESA-2025-2546
OPENSUSE-SU-2025:15667-1
SUSE-SU-2025:4087-1
SUSE-SU-2025_4087-1
USN-7843-1

Affected Products

Debian
Linuxmint
Netty
Red Os
Suse
Ubuntu