PT-2026-38379 · Netty+2 · Netty+2

·

CVE-2026-42587

·

Published

2026-05-05

·

Updated

2026-09-03

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Netty versions prior to 4.1.133.Final Netty versions prior to 4.2.13.Final
Description HttpContentDecompressor and DelegatingDecompressorFrameListener (used for HTTP/2 connections) utilize a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks—a technique where a small compressed payload expands to a massive size to exhaust system resources. While this limit is enforced for gzip and deflate encodings via ZlibDecoder, it is ignored for br (Brotli), zstd, or snappy encodings. An attacker can bypass the configured limit by sending a compressed payload with Content-Encoding: br, zstd, or snappy, leading to unbounded memory allocation and out-of-memory denial of service.
Recommendations Update to version 4.1.133.Final or later. Update to version 4.2.13.Final or later.

Exploit

Fix

DoS

Resource Exhaustion

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09829
CLEANSTART-2026-BK55944
CLEANSTART-2026-BO52019
CLEANSTART-2026-CP46043
CLEANSTART-2026-DD05788
CLEANSTART-2026-DT81884
CLEANSTART-2026-EG39405
CLEANSTART-2026-FV79231
CLEANSTART-2026-FX60287
CLEANSTART-2026-FZ22182
CLEANSTART-2026-GX01236
CLEANSTART-2026-GX44743
CLEANSTART-2026-IY44515
CLEANSTART-2026-KL03760
CLEANSTART-2026-LB41442
CLEANSTART-2026-LE11246
CLEANSTART-2026-MT41286
CLEANSTART-2026-MX76059
CLEANSTART-2026-NE94194
CLEANSTART-2026-NW12954
CLEANSTART-2026-PO27799
CLEANSTART-2026-RN56220
CLEANSTART-2026-RU36468
CLEANSTART-2026-VJ37814
CLEANSTART-2026-VP53607
CLEANSTART-2026-YY96069
CVE-2026-42587
GHSA-F6HV-JMP6-3VWV
OPENSUSE-SU-2026:10795-1
RHSA-2026:53644
SUSE-SU-2026:2308-1

Affected Products

Confluence
Netty
Red Os