PT-2026-48916 · Netty+1 · Netty+1
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Netty versions prior to 4.1.135.Final
Netty versions prior to 4.2.15.Final
Description
Netty HTTP/2 max header size handling allows for an attack similar to HTTP/2 Rapid Reset. When a client sends the
SETTINGS MAX HEADER LIST SIZE setting, the framework reads the request, proxies it to the origin, and attempts to produce a response, but subsequently creates an exception while writing the response headers. This results in a functional behavior similar to an HTTP/2 reset attack but with a different on-the-wire signature.Recommendations
Update to version 4.1.135.Final
Update to version 4.2.15.Final
Exploit
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netty
Red Os