{"id":"ROOT-APP-MAVEN-CVE-2026-42585","summary":"CVE-2026-42585 in io.root.io.netty:netty-codec-http - Patched by Root","details":"Root has patched CVE-2026-42585 in the io.root.io.netty:netty-codec-http package for Root:Maven. Multiple fixed versions available.","modified":"2026-05-29T13:30:11.614101661Z","published":"2026-05-29T08:54:35Z","upstream":["CVE-2026-42585"],"database_specific":{"distro":"maven","distro_version":"","source":"Root","severity":"MEDIUM"},"affected":[{"package":{"name":"io.root.io.netty:netty-codec-http","ecosystem":"Root:Maven"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.1.126.Final-root.io.12"},{"fixed":"4.1.126.Final-root.io.13"},{"fixed":"4.1.115.Final-root.io.3"},{"fixed":"4.1.115.Final-root.io.4"},{"fixed":"4.1.115.Final-root.io.5"},{"fixed":"4.1.115.Final-root.io.6"},{"fixed":"4.1.126.Final-root.io.14"}]}],"database_specific":{"total_fixed_versions":7,"root_patched":true,"upstream_version":"4.1.126.Final","root_patch_version":"root.io.14","source":"https://api.root.io/external/osv/ROOT-APP-MAVEN-CVE-2026-42585.json","all_fixed_versions":["4.1.126.Final-root.io.12","4.1.126.Final-root.io.13","4.1.115.Final-root.io.3","4.1.115.Final-root.io.4","4.1.115.Final-root.io.5","4.1.115.Final-root.io.6","4.1.126.Final-root.io.14"]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"}]}