Command Injection in Netty - CVE-2025-59419
Published: October 15, 2025
Vulnerability identifier: #VU117297
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-59419
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary SMTP commands.
The vulnerability exists due to insufficient input validation in the SMTP codec. A remote attacker can pass specially crafted data to the application and forge arbitrary emails from the trusted server.
Affected software
Netty
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Development Tools Module
SUSE Package Hub 15
openSUSE Leap
Ubuntu
openEuler
Netezza Appliance
Storage Defender Copy Data Management
Guardium Data Security Center (GDSC)
DataStage on Cloud Pak for Data
Oracle Business Intelligence Enterprise Edition
watsonx.data
Oracle GoldenGate Big Data and Application Adapters
netty-tcnative-debugsource
netty-tcnative-javadoc
netty-tcnative
netty (Ubuntu package)
netty
netty-help
netty (Debian package)
netty-javadoc
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Development Tools Module
SUSE Package Hub 15
openSUSE Leap
Ubuntu
openEuler
Netezza Appliance
Storage Defender Copy Data Management
Guardium Data Security Center (GDSC)
DataStage on Cloud Pak for Data
Oracle Business Intelligence Enterprise Edition
watsonx.data
Oracle GoldenGate Big Data and Application Adapters
netty-tcnative-debugsource
netty-tcnative-javadoc
netty-tcnative
netty (Ubuntu package)
netty
netty-help
netty (Debian package)
netty-javadoc
How to mitigate CVE-2025-59419
Install updates from vendor's website.
Netty - addressed in versions 4.1.128, 4.2.7
Netezza Appliance - update to 1.0.0.1
Storage Defender Copy Data Management - update to 2.3.1.0
watsonx.data - update to 2.3.1
Guardium Data Security Center (GDSC) - update to 3.8.5
DataStage on Cloud Pak for Data - update to 5.3.0
netty-tcnative-debugsource - update to 2.0.74-150200.3.33.1
netty-tcnative-javadoc - update to 2.0.74-150200.3.33.1
netty-tcnative - update to 2.0.74-150200.3.33.1
netty (Ubuntu package) - addressed in versions 1:4.1.7-4ubuntu0.1+esm4, 1:4.1.45-1ubuntu0.1~esm3, 1:4.1.48-4+deb11u2ubuntu0.1~esm2, 1:4.1.48-9ubuntu0.1~esm2, 1:4.1.48-10ubuntu0.25.04.1, 1:4.1.48-10ubuntu0.25.10.1
netty - addressed in versions 4.1.13-21, 4.1.13-24
netty-help - addressed in versions 4.1.13-21, 4.1.13-24
netty (Debian package) - addressed in versions 1:4.1.48-7+deb12u2, 1:4.1.48-10+deb13u1
netty - update to 4.1.128-150200.4.37.1
netty-javadoc - update to 4.1.128-150200.4.37.1
Netezza Appliance - update to 1.0.0.1
Storage Defender Copy Data Management - update to 2.3.1.0
watsonx.data - update to 2.3.1
Guardium Data Security Center (GDSC) - update to 3.8.5
DataStage on Cloud Pak for Data - update to 5.3.0
netty-tcnative-debugsource - update to 2.0.74-150200.3.33.1
netty-tcnative-javadoc - update to 2.0.74-150200.3.33.1
netty-tcnative - update to 2.0.74-150200.3.33.1
netty (Ubuntu package) - addressed in versions 1:4.1.7-4ubuntu0.1+esm4, 1:4.1.45-1ubuntu0.1~esm3, 1:4.1.48-4+deb11u2ubuntu0.1~esm2, 1:4.1.48-9ubuntu0.1~esm2, 1:4.1.48-10ubuntu0.25.04.1, 1:4.1.48-10ubuntu0.25.10.1
netty - addressed in versions 4.1.13-21, 4.1.13-24
netty-help - addressed in versions 4.1.13-21, 4.1.13-24
netty (Debian package) - addressed in versions 1:4.1.48-7+deb12u2, 1:4.1.48-10+deb13u1
netty - update to 4.1.128-150200.4.37.1
netty-javadoc - update to 4.1.128-150200.4.37.1
External References
Related Security Bulletins
- SMTP injection in Netty
- openEuler 22.03 LTS SP4 update for netty
- openEuler 22.03 LTS SP3 update for netty
- openEuler 20.03 LTS SP4 update for netty
- openEuler 24.03 LTS SP1 update for netty
- openEuler 24.03 LTS update for netty
- Ubuntu update for netty
- openEuler 24.03 LTS SP2 update for netty
- SUSE update for netty, netty-tcnative
- Multiple vulnerabilities in IBM Guardium Data Security Center
- IBM Netezza Appliance update for Netty
- IBM DataStage on Cloud Pak for Data update for Netty
- Multiple vulnerabilities in Oracle GoldenGate Big Data and Application Adapters
- IBM watsonx.data update for Netty
- Debian update for netty
- Multiple vulnerabilities in Oracle Business Intelligence Enterprise Edition
- Multiple vulnerabilities in IBM Storage Defender Copy Data Management