An Azure platform as a service for running Spring Boot applications at cloud scale. Previously known as Azure Spring Cloud.
Hello Goyal, Charu,
Welcome to the Microsoft Q&A and thank you for posting your questions here.
I understand that you are validating whether CVE-2026-42577 applies to your Azure Spring Apps project using Netty 4.1.133.Final.
The root cause is not an actual exposed vulnerability in your application, but a CVE scope mismatch or scanner false positive. CVE-2026-42577 applies to io.netty:netty-transport-native-epoll 4.2.x only, specifically versions 4.2.0.Final through 4.2.12.Final, and is fixed in 4.2.13.Final. Your project is currently on Netty 4.1.133.Final, which is outside the affected branch and therefore not impacted by this CVE. - https://github.com/netty/netty/security/advisories/GHSA-rwm7-x88c-3g2p, https://github.com/advisories/GHSA-rwm7-x88c-3g2p
Therefore,
- Do not upgrade to Netty 4.2.x for CVE-2026-42577
- Keep Netty at 4.1.133.Final
- Close CVE-2026-42577 as Not Applicable / False Positive
- Do not trigger Spring Boot or platform architectural upgrades for this CVE
- Use dependency evidence to update the security exception or vulnerability disposition
The reason for the above is because Netty 4.1 and Netty 4.2 should not be mixed on the same classpath, and moving to Netty 4.2 requires a coordinated migration decision rather than a CVE-only patch action. - https://netty.io/wiki/netty-4.2-migration-guide.html, https://github.com/netty/netty/wiki/Netty-4.2-Migration-Guide
After validating the dependency tree and confirming that the runtime version is 4.1.133.Final, the CVE should be marked as not applicable, since the affected range is limited to the 4.2.x epoll transport branch. Netty 4.1.133.Final is also a security release that addresses other Netty CVEs in the 4.1.x line. - https://netty.io/news/2026/05/04/4-1-133-Final.html
Use the below resource links for more reading and steps:
- Netty GitHub Security Advisory: https://github.com/netty/netty/security/advisories/GHSA-rwm7-x88c-3g2p
- GitHub Advisory Database: https://github.com/advisories/GHSA-rwm7-x88c-3g2p
- Netty 4.1.133.Final Release Notes: https://netty.io/news/2026/05/04/4-1-133-Final.html
- Netty 4.2 Migration Guide: https://netty.io/wiki/netty-4.2-migration-guide.html
I hope this is helpful! Do not hesitate to let me know if you have any other questions, steps or clarifications.
Please don't forget to close up the thread here by upvoting and accept it as an answer if it is helpful.