{"id":"ECHO-9e12-62af-9330","summary":"Reopened: bumped to 3.10.6.Final, which is still vulnerable. Bumped version 3.10.6.Final is still in \u003c 4.0.0; upstream fix none","modified":"2026-09-30T11:45:42.871177602Z","published":"2026-09-28T00:00:19.161Z","withdrawn":"2026-09-30T11:25:17.071Z","upstream":["CVE-2021-43797","GHSA-wx5j-54mm-rqqq"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2021-43797"},{"type":"WEB","url":"https://github.com/advisories/GHSA-wx5j-54mm-rqqq"}],"affected":[{"package":{"name":"netty","ecosystem":"Echo:Maven","purl":"pkg:maven/netty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-9e12-62af-9330.json"}}],"schema_version":"1.9.0"}