A vulnerability identified as problematic has been detected in Netty. Affected is the function
setVaryHeader of the file io.netty.handler.codec.http.cors.CorsHandler of the component CorsHandler. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2026-59903. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.