Hi, The following vulnerability was published for netty. CVE-2026-100666[0]: | Netty's HttpServerCodec (io.netty:netty-codec-http) in versions | 4.2.0.Final through 4.2.16.Final and in versions up to and including | 4.1.136.Final pairs each outbound response with an inbound request | by calling pollMethod() once per response, including for 1xx | informational responses. If a client pipelines an HTTP/1.1 GET | carrying an Expect: 100-continue header followed by a HEAD request, | the 100 Continue response consumes the queued GET method, so the | subsequent 200 OK for the GET is paired with HEAD and its body is | dropped, while the following 200 OK for the HEAD request is written | with a body. This desynchronizes HTTP parsing on the connection: the | GET entity is never delivered and the HEAD response body is | interpreted as the GET body, resulting in response splitting and | unsafe connection reuse. Fixed in 4.2.17.Final and 4.1.137.Final. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-100666 https://www.cve.org/CVERecord?id=CVE-2026-100666 [1] https://github.com/netty/netty/security/advisories/GHSA-2g6j-r8q9-5hr8 Please adjust the affected versions in the BTS as needed. Regards, Salvatore