PT-2026-61744 · Netty · Netty

CVE-2026-55831

·

Published

2026-07-07

·

Updated

2026-08-04

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Netty versions prior to 4.1.136.Final Netty versions prior to 4.2.16.Final
Description The SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length limit and materializes every unique setting ID in DefaultSpdySettingsFrame. This allows a remote SPDY/3.1 peer to send a syntactically valid SETTINGS frame of approximately 2 MiB, resulting in the creation of 262,144 map entries. This process amplifies network input into heap growth and ordered-map insertion work, leading to a denial of service.
Recommendations Update to version 4.1.136.Final. Update to version 4.2.16.Final.

Exploit

Fix

DoS

Resource Exhaustion

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-10237
CVE-2026-55831
GHSA-6JQX-86GH-F27W
OPENSUSE-SU-2026:11394-1
SUSE-SU-2026:3482-1

Affected Products

Netty