Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Casting a Net(ty) for Bugs, and Catching a Big One (CVE-2025-59419)

depthfirst.com | vulnerability | Medium | CVE-2025-59419 | #vulnerability-research | #java | #command-injection | #netty | #smtp | #cve-2025-59419

Summary

Netty's SMTP codec allowed CRLF injection in user input, letting attackers append forged mail commands that bypass SPF, DKIM and DMARC; depthfirst's agent found it, tracked as CVE-2025-59419.
CVSS
5.5
Published
Collected

original ↗

Related coverage

back