SCA: security update for io.netty:netty-codec-smtp (GHSA-jq43-27x9-3v86)

medium Tenable Self-Hosted Container Security Plugin ID 435627

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.128.Final
and 4.2.7.Final, the SMTP codec in Netty contains an SMTP command injection vulnerability due to
insufficient input validation for Carriage Return (\r) and Line Feed (\n) characters in user-supplied
parameters. The vulnerability exists in io.netty.handler.codec.smtp.DefaultSmtpRequest, where parameters
are directly concatenated into the SMTP command string without sanitization. When methods such as
SmtpRequests.rcpt(recipient) are called with a malicious string containing CRLF sequences, attackers can
inject arbitrary SMTP commands. Because the injected commands are sent from the server's trusted IP
address, resulting emails will likely pass SPF and DKIM authentication checks, making them appear
legitimate. This allows remote attackers who can control SMTP command parameters (such as email
recipients) to forge arbitrary emails from the trusted server, potentially impersonating executives and
forging high-stakes corporate communications. This issue has been patched in versions 4.1.129.Final and
4.2.8.Final. No known workarounds exist. (CVE-2025-59419)

See Also

https://github.com/advisories/GHSA-jq43-27x9-3v86

Plugin Details

Severity: Medium

ID: 435627

Version: Revision 1.18

Type: Local

Family: SCA Checks

Published: 10/15/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.73

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2025-59419

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 6.9

Threat Score: 5.5

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/15/2025

Vulnerability Publication Date: 10/15/2025

Reference Information

CVE: CVE-2025-59419