Hi Team, for CVE-2026-42577, its mentioned in the portal : "All versions of 4.2.x netty-transport-native-epoll up to and including 4.2.12.Final" — which explicitly scopes it to 4.2.x only. current State: project uses 4.1.133.Final (4.1.x branch),

Goyal, Charu 0 Reputation points
2026-05-20T05:52:34.75+00:00

Hi Team, 

for CVE-2026-42577, its mentioned in the portal :

"All versions of 4.2.x netty-transport-native-epoll up to and including 4.2.12.Final" — which explicitly scopes it to 4.2.x only.

  • current State: project uses 4.1.133.Final (4.1.x branch), which has no equivalent vulnerability. repo: optum-rx-pbm/RxCometUserMS: RxCometUserMS fix: fix: upgrade netty to 4.1.133.Final to resolve CVE-2026-42579, CVE-20… by cgoyal4_uhg · Pull Reques…
    We are currently dependent on the patched version status for this CVE. There are other vulnerabilities that require Netty 4.1.133.Final as a fix, and those CVEs have clearly specified the fixed version ranges (e.g., 4.1.x  to 4.1.133.Final and 4.2.x to 4.2.13.Final). Upgrading to 4.2.x specifically for this CVE-2026-42577 would result in double work if we later need to upgrade. trusted sources state the affected range for CVE-2026-42577 is 4.2.0.Final to 4.2.12.Final, If it is verified that all versions below 4.2.13.Final are affected, we would need to make significant changes, including upgrading all repositories to Spring Boot 4.x (which supports Netty 4.2.x). This would require an architectural decision.
Azure Spring Apps
Azure Spring Apps

An Azure platform as a service for running Spring Boot applications at cloud scale. Previously known as Azure Spring Cloud.

0 comments No comments

1 answer

Sort by: Most helpful
  1. Sina Salam 31,456 Reputation points Volunteer Moderator
    2026-05-20T16:26:53.0633333+00:00

    Hello Goyal, Charu,

    Welcome to the Microsoft Q&A and thank you for posting your questions here.

    I understand that you are validating whether CVE-2026-42577 applies to your Azure Spring Apps project using Netty 4.1.133.Final.

    The root cause is not an actual exposed vulnerability in your application, but a CVE scope mismatch or scanner false positive. CVE-2026-42577 applies to io.netty:netty-transport-native-epoll 4.2.x only, specifically versions 4.2.0.Final through 4.2.12.Final, and is fixed in 4.2.13.Final. Your project is currently on Netty 4.1.133.Final, which is outside the affected branch and therefore not impacted by this CVE. - https://github.com/netty/netty/security/advisories/GHSA-rwm7-x88c-3g2p, https://github.com/advisories/GHSA-rwm7-x88c-3g2p

    Therefore,

    • Do not upgrade to Netty 4.2.x for CVE-2026-42577
    • Keep Netty at 4.1.133.Final
    • Close CVE-2026-42577 as Not Applicable / False Positive
    • Do not trigger Spring Boot or platform architectural upgrades for this CVE
    • Use dependency evidence to update the security exception or vulnerability disposition

    The reason for the above is because Netty 4.1 and Netty 4.2 should not be mixed on the same classpath, and moving to Netty 4.2 requires a coordinated migration decision rather than a CVE-only patch action. - https://netty.io/wiki/netty-4.2-migration-guide.html, https://github.com/netty/netty/wiki/Netty-4.2-Migration-Guide

    After validating the dependency tree and confirming that the runtime version is 4.1.133.Final, the CVE should be marked as not applicable, since the affected range is limited to the 4.2.x epoll transport branch. Netty 4.1.133.Final is also a security release that addresses other Netty CVEs in the 4.1.x line. - https://netty.io/news/2026/05/04/4-1-133-Final.html

    Use the below resource links for more reading and steps:

    I hope this is helpful! Do not hesitate to let me know if you have any other questions, steps or clarifications.


    Please don't forget to close up the thread here by upvoting and accept it as an answer if it is helpful.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.