FrankChen021 commented on code in PR #20236:
URL: https://github.com/apache/druid/pull/20236#discussion_r3940684853


##########
owasp-dependency-check-suppressions.xml:
##########
@@ -274,6 +320,61 @@
     <cve>CVE-2025-58057</cve> <!-- Netty 3.x not affected; compression issue 
only in 4.x -->
     <cve>CVE-2026-33870</cve> <!-- We don't use HttpPostRequestDecoder -->
     <cve>CVE-2026-33871</cve> <!-- Netty 3.x not affected; HTTP/2 issues only 
in 4.x -->
+    <cve>CVE-2026-44893</cve> <!-- We don't use the HAProxy codec -->
+    <cve>CVE-2026-44250</cve> <!-- We don't use the Redis codec -->
+    <cve>CVE-2026-48059</cve> <!-- We don't use the HAProxy codec -->
+    <cve>CVE-2026-44890</cve> <!-- We don't use the Redis codec -->
+    <cve>CVE-2026-44891</cve> <!-- We don't use the STOMP codec -->
+    <cve>CVE-2026-50011</cve> <!-- We don't use the Redis codec -->
+    <cve>CVE-2026-59901</cve> <!-- We don't use Netty's Bzip2Decoder; Druid 
uses Apache Commons Compress for bzip2 -->
+    <cve>CVE-2026-62380</cve> <!-- We don't use the SOCKS codec; Druid uses 
HTTP CONNECT proxy tunneling -->
+    <cve>CVE-2026-59898</cve> <!-- Server-side WebSocket vulnerability; 
Druid's HTTP server is Jetty, not Netty -->
+    <cve>CVE-2026-59899</cve> <!-- Server-side HttpContentEncoder 
vulnerability; Druid uses Netty 3.x as HTTP client only -->
+    <cve>CVE-2026-42587</cve> <!-- Affects brotli/zstd/snappy decompression 
added in Netty 4.x; Netty 3.x only supports gzip/deflate -->
+    <cve>CVE-2026-42586</cve> <!-- We don't use the Redis codec -->
+    <cve>CVE-2026-44248</cve> <!-- We don't use the MQTT codec -->
+    <cve>CVE-2026-44249</cve> <!-- We don't use Netty's IpSubnetFilterRule; 
Druid uses Jetty for HTTP access control -->
+    <cve>CVE-2026-45416</cve> <!-- Server-side TLS SNI vulnerability; Druid 
uses Netty 3.x as TLS client only, never as a server -->
+    <cve>CVE-2026-42581</cve> <!-- Server-side HTTP request smuggling; Druid's 
HTTP server is Jetty, not Netty -->
+    <cve>CVE-2026-45674</cve> <!-- Affects netty-resolver-dns which Druid 
doesn't use; Druid uses JDK DNS resolution -->
+    <cve>CVE-2026-48006</cve> <!-- We don't use the Redis codec -->
+    <cve>CVE-2026-42585</cve> <!-- Server-side HTTP request smuggling; Druid's 
HTTP server is Jetty, not Netty -->
+    <cve>CVE-2026-42584</cve> <!-- HttpClientCodec response desynchronization 
in Netty 4.x codec; Druid uses Netty 3.x's HttpClientCodec which has a 
different implementation -->

Review Comment:
   [P1] Do not suppress the Netty response desynchronization
   
   The “Netty 4.x / different implementation” justification is not safe for 
Druid's client. In the local Netty 3.10.6 source, HttpClientCodec.Decoder 
special-cases only status 100 before queue.poll(), while HttpMessageDecoder 
treats all 1xx statuses (including 103) as empty. NettyHttpClient calls 
finishRequest() for every non-chunked response and returns the channel to 
ResourcePool at lines 258-259 and 317-335. Thus a server can send 103, make 
Druid return and reuse the socket, and deliver the final response after the 
next request has been written. Remove this CVE from the Netty 3 suppression or 
explicitly track and mitigate the exposure until the client waits for final 
responses or is patched/upgraded.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to