[GHSA-prj3-ccx8-p6x4] Netty affected by MadeYouReset HTTP/2 DDoS vulnerability #6237
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Updates
Comments
There is no
grpc-netty-shaded:1.175.0
version — that looks like a typo.The correct version available on Maven Central is
1.75.0
, and it already bundles Netty4.1.124.Final
which contains the fix for CVE-2025-55163.So the "fixed version" in the Trivy database should point to
1.75.0
, not1.175.0
.