com.alibaba.nacos:nacos-client:3.2.3最新版本存在CVE-2026-33871漏洞
envgap__alibaba__nacos-15767
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- In a clean container the reported failure did not reproduce, or the known fix did not make the project run.
02 / ENVIRONMENT RECIPE
- Base commit
b657faaafd5d641be32f36dcfb58c7588c3d0420- Manifest
pom.xml- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
alibaba/nacos #15767 · read the original issue
Description Details com.alibaba.nacos:nacos-client:3.2.3最新版本存在https://github.com/advisories/GHSA-w9fj-cfpg-grvv漏洞 1、打开依赖的代码目录com\alibaba\nacos\shaded\io\grpc\netty\shaded\io\netty\handler\codec 发现DefaultHttp2FrameReader.java存在https://github.com/advisories/GHSA-w9fj-cfpg-grvv漏洞,漏洞的代码示例如下: test 2、并且从 io.grpc.netty.shaded.io.netty.versions.properties 中提取到: netty-common.version = 4.1.127.Final,这个版本也存在https://github.com/advisories/GHSA-w9fj-cfpg-grvv漏洞 PoC Impact 详细链接见:https://github.com/advisories/GHSA-w9fj-cfpg-grvv
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]