critical · CVSS v3 9.1
CVE-2026-93576
Netty netty-codec-smtp — SMTP command-name field is not CRLF-validated (incomplete fix of CVE-2025-59419)
Description
Netty netty-codec-smtp — SMTP command-name field is not CRLF-validated (incomplete fix of CVE-2025-59419)
Scores
- Severity
- critical
- CVSS v2
- 7.8
- CVSS v3
- 9.1
- CVSS v4
- —
- EPSS
- —