PT-2026-47604 · Unknown+1 · Netty-Codec-Haproxy+1

·

CVE-2026-44893

·

Published

2026-06-08

·

Updated

2026-09-03

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions netty-codec-haproxy versions prior to 4.1.135.Final netty-codec-haproxy versions prior to 4.2.15.Final
Description A flaw in the netty-codec-haproxy component of the Netty network application framework allows a remote attacker to cause a Denial of Service (DoS) condition. By sending a specially crafted HAProxy message with a malformed PP2 TYPE SSL TLV (Type-Length-Value) header where the length is set below 5, the readNextTLV() function in HAProxyMessage triggers an IndexOutOfBoundsException. Because the HAProxyMessageDecoder only catches HAProxyProtocolException, this exception propagates, preventing the release of retained memory on the pooled cumulation buffer and leading to a memory leak.
Recommendations Update netty-codec-haproxy to version 4.1.135.Final or later. Update netty-codec-haproxy to version 4.2.15.Final or later.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-BK55944
CLEANSTART-2026-BO52019
CLEANSTART-2026-DT81884
CLEANSTART-2026-EG39405
CLEANSTART-2026-GX44743
CLEANSTART-2026-KL03760
CLEANSTART-2026-NE94194
CLEANSTART-2026-RS65756
CLEANSTART-2026-SH44648
CLEANSTART-2026-VP53607
CLEANSTART-2026-YY96069
CVE-2026-44893
GHSA-CC37-9Q2J-3HFV
OPENSUSE-SU-2026:11033-1
RHSA-2026:53644
SUSE-SU-2026:2802-1

Affected Products

Red Os
Netty-Codec-Haproxy