FrankChen021 commented on code in PR #20236:
URL: https://github.com/apache/druid/pull/20236#discussion_r3933923058
##########
owasp-dependency-check-suppressions.xml:
##########
@@ -274,6 +320,69 @@
<cve>CVE-2025-58057</cve> <!-- Netty 3.x not affected; compression issue
only in 4.x -->
<cve>CVE-2026-33870</cve> <!-- We don't use HttpPostRequestDecoder -->
<cve>CVE-2026-33871</cve> <!-- Netty 3.x not affected; HTTP/2 issues only
in 4.x -->
+ <cve>CVE-2026-44893</cve> <!-- We don't use the HAProxy codec -->
+ <cve>CVE-2026-44250</cve> <!-- We don't use the Redis codec -->
+ <cve>CVE-2026-48059</cve> <!-- We don't use the HAProxy codec -->
+ <cve>CVE-2026-44890</cve> <!-- We don't use the Redis codec -->
+ <cve>CVE-2026-44891</cve> <!-- We don't use the STOMP codec -->
+ <cve>CVE-2026-50011</cve> <!-- We don't use the Redis codec -->
+ <cve>CVE-2026-59901</cve> <!-- We don't use Netty's Bzip2Decoder; Druid
uses Apache Commons Compress for bzip2 -->
+ <cve>CVE-2026-62380</cve> <!-- We don't use the SOCKS codec; Druid uses
HTTP CONNECT proxy tunneling -->
+ <cve>CVE-2026-59898</cve> <!-- Server-side WebSocket vulnerability;
Druid's HTTP server is Jetty, not Netty -->
+ <cve>CVE-2026-59899</cve> <!-- Server-side HttpContentEncoder
vulnerability; Druid uses Netty 3.x as HTTP client only -->
+ <cve>CVE-2026-42587</cve> <!-- Affects brotli/zstd/snappy decompression
added in Netty 4.x; Netty 3.x only supports gzip/deflate -->
+ <cve>CVE-2026-42586</cve> <!-- We don't use the Redis codec -->
+ <cve>CVE-2026-44248</cve> <!-- We don't use the MQTT codec -->
+ <cve>CVE-2026-44249</cve> <!-- We don't use Netty's IpSubnetFilterRule;
Druid uses Jetty for HTTP access control -->
+ <cve>CVE-2026-45416</cve> <!-- Server-side TLS SNI vulnerability; Druid
uses Netty 3.x as TLS client only, never as a server -->
+ <cve>CVE-2026-42581</cve> <!-- Server-side HTTP request smuggling; Druid's
HTTP server is Jetty, not Netty -->
+ <cve>CVE-2026-45674</cve> <!-- Affects netty-resolver-dns which Druid
doesn't use; Druid uses JDK DNS resolution -->
+ <cve>CVE-2026-48006</cve> <!-- We don't use the Redis codec -->
+ <cve>CVE-2026-42585</cve> <!-- Server-side HTTP request smuggling; Druid's
HTTP server is Jetty, not Netty -->
+ <cve>CVE-2026-42584</cve> <!-- HttpClientCodec response desynchronization
in Netty 4.x codec; Druid uses Netty 3.x's HttpClientCodec which has a
different implementation -->
Review Comment:
Thanks for checking. I re-verified this against the current head and the
local `netty-3.10.6.Final` source. The suppression is still present at this
line, but the comment's “Netty 4.x codec; different implementation”
justification does not hold for the client Druid actually uses:
- `org.jboss.netty.handler.codec.http.HttpClientCodec` skips `queue.poll()`
only for status 100; status 103 falls through to `queue.poll()`, while the base
decoder still treats all 1xx responses as empty.
- `NettyHttpClient` treats every non-chunked response as complete, removes
its handler, and returns the channel to `ResourcePool`. A server can therefore
send an interim 103, cause the channel to be reused, and then deliver the
original final response after the next request has been written.
That is the same unsafe response/request pairing described by
CVE-2026-42584. Please remove this CVE from the Netty 3 suppression until this
client waits for the final response or is patched/upgraded. If release timing
requires accepting the exposure, it should be tracked as an explicit risk
rather than suppressed as unaffected.
Reviewed 1 of 1 changed files.
<!-- mergelens:review -->
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]