PT-2026-28108 · Netty+2 · Netty+2

·

CVE-2026-33871

·

Published

2026-03-24

·

Updated

2026-08-18

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Netty versions prior to 4.1.132.Final and versions prior to 4.2.10.Final
Description Netty, an asynchronous, event-driven network application framework, is susceptible to a Denial of Service (DoS) attack. A remote user can exploit this by sending a flood of CONTINUATION frames to a Netty HTTP/2 server. The server does not limit the number of CONTINUATION frames it accepts, and existing size-based protections are bypassed when zero-byte frames are used. This allows an attacker to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. The issue resides in the DefaultHttp2FrameReader component, specifically within the verifyContinuationFrame() function, which lacks a frame count check. The HeadersBlockBuilder.addFragment() function also allows bypassing the byte limit with zero-byte frames.
Recommendations Upgrade to Netty version 4.1.132.Final or later. Upgrade to Netty version 4.2.10.Final or later.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09558
CLEANSTART-2026-AV84730
CLEANSTART-2026-BK55944
CLEANSTART-2026-BO52019
CLEANSTART-2026-CF62516
CLEANSTART-2026-CP46043
CLEANSTART-2026-DD05788
CLEANSTART-2026-DT81884
CLEANSTART-2026-DY69070
CLEANSTART-2026-EG39405
CLEANSTART-2026-EZ90321
CLEANSTART-2026-FV79231
CLEANSTART-2026-FX60287
CLEANSTART-2026-FZ22182
CLEANSTART-2026-GN46454
CLEANSTART-2026-GX44743
CLEANSTART-2026-IS05941
CLEANSTART-2026-IY44515
CLEANSTART-2026-JU62349
CLEANSTART-2026-KB76878
CLEANSTART-2026-KL03760
CLEANSTART-2026-LB41442
CLEANSTART-2026-LE11246
CLEANSTART-2026-MT41286
CLEANSTART-2026-MX76059
CLEANSTART-2026-NE94194
CLEANSTART-2026-NW12954
CLEANSTART-2026-QI14017
CLEANSTART-2026-RN56220
CLEANSTART-2026-RS65756
CLEANSTART-2026-RU36468
CLEANSTART-2026-SH44648
CLEANSTART-2026-SQ91016
CLEANSTART-2026-SR31778
CLEANSTART-2026-SV95049
CLEANSTART-2026-TK07726
CLEANSTART-2026-VH41554
CLEANSTART-2026-VJ37814
CLEANSTART-2026-VN28553
CLEANSTART-2026-VP53607
CLEANSTART-2026-WG59699
CLEANSTART-2026-WK99982
CLEANSTART-2026-WT54034
CLEANSTART-2026-YX54699
CLEANSTART-2026-YY96069
CVE-2026-33871
GHSA-W9FJ-CFPG-GRVV
OPENSUSE-SU-2026:10463-1
RHSA-2026:18054
RHSA-2026:18055
SUSE-SU-2026:1353-1

Affected Products

Confluence
Netty
Red Os