PT-2026-61745 · Netty · Netty
CVE-2026-55833
·
Published
2026-07-14
·
Updated
2026-08-04
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Netty versions prior to 4.1.136.Final
Netty versions prior to 4.2.16.Final
Description
An issue exists in the SPDY protocol implementation where header decoding continues inflating zlib-compressed header blocks even after the raw header parser has exceeded the
maxHeaderSize and marked the frame as truncated in SpdyFrameCodec. This allows a remote attacker to send a small compressed HEADERS block that expands into significantly larger raw header data, leading to compression-amplified CPU and memory allocation churn, which can result in a denial of service.Recommendations
Update to version 4.1.136.Final or later.
Update to version 4.2.16.Final or later.
Exploit
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netty