PT-2026-61744 · Netty · Netty
CVE-2026-55831
·
Published
2026-07-07
·
Updated
2026-08-04
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Netty versions prior to 4.1.136.Final
Netty versions prior to 4.2.16.Final
Description
The SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length limit and materializes every unique setting ID in
DefaultSpdySettingsFrame. This allows a remote SPDY/3.1 peer to send a syntactically valid SETTINGS frame of approximately 2 MiB, resulting in the creation of 262,144 map entries. This process amplifies network input into heap growth and ordered-map insertion work, leading to a denial of service.Recommendations
Update to version 4.1.136.Final.
Update to version 4.2.16.Final.
Exploit
Fix
DoS
Resource Exhaustion
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Netty