PT-2026-62422 · Netty · Netty

CVE-2026-56816

·

Published

2026-07-21

·

Updated

2026-08-07

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Netty versions prior to 4.2.16.Final
Description Netty's Http3FrameCodec buffers incoming data for HTTP/3 reserved frame types up to the wire-specified payload length without limits. The decodeFrame() function trusts the payLoadLength variable, which allows an attacker to open multiple QUIC streams and send reserved frames with excessively large payload lengths, leading to memory exhaustion and denial of service.
Recommendations Update to version 4.2.16.Final.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56816
GHSA-HPCC-26XQ-25FV

Affected Products

Netty