PT-2026-47604 · Unknown+1 · Netty-Codec-Haproxy+1
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
netty-codec-haproxy versions prior to 4.1.135.Final
netty-codec-haproxy versions prior to 4.2.15.Final
Description
A flaw in the netty-codec-haproxy component of the Netty network application framework allows a remote attacker to cause a Denial of Service (DoS) condition. By sending a specially crafted HAProxy message with a malformed PP2 TYPE SSL TLV (Type-Length-Value) header where the length is set below 5, the
readNextTLV() function in HAProxyMessage triggers an IndexOutOfBoundsException. Because the HAProxyMessageDecoder only catches HAProxyProtocolException, this exception propagates, preventing the release of retained memory on the pooled cumulation buffer and leading to a memory leak.Recommendations
Update netty-codec-haproxy to version 4.1.135.Final or later.
Update netty-codec-haproxy to version 4.2.15.Final or later.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Red Os
Netty-Codec-Haproxy