1.
depthfirst.com | vulnerability | Medium | | original ↗ | #vulnerability-research | #java | #command-injection | #netty
Netty's SMTP codec allowed CRLF injection in user input, letting attackers append forged mail commands that bypass SPF, DKIM and DMARC; depthfirst's agent found it, tracked as CVE-2025-59419.
Skip to content