Null Byte Interaction Error (Poison Null Byte) in Netty - #VU141322
Published: August 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to spoof domains and inject authentication data.
The vulnerability exists due to null byte interaction error in Socks4ClientEncoder and Socks5ClientEncoder when encoding SOCKS4 or SOCKS5 fields containing embedded null bytes or control characters. A remote attacker can supply specially crafted domain names, user identifiers, usernames, or passwords to spoof domains and inject authentication data.
Different proxy implementations may truncate null-terminated values differently, which can cause protocol ambiguity in SOCKS4 and altered interpretation of SOCKS5 destination and credential fields.