PT-2026-63549 · Netty · Netty

CVE-2026-59901

·

Published

2026-07-22

·

Updated

2026-08-06

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Netty versions prior to 4.1.136.Final Netty versions prior to 4.2.16.Final
Description The Bzip2Decoder handler in the compression codec pipeline is susceptible to a denial-of-service attack. A malformed bzip2 stream can trigger an infinite loop within the run-length encoding (RLE) state machine in the Bzip2BlockDecompressor.read() function, permanently capturing the event-loop thread.
Recommendations Update to version 4.1.136.Final or later. Update to version 4.2.16.Final or later.

Exploit

Fix

DoS

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59901
GHSA-558V-64GR-WGG4
OPENSUSE-SU-2026:11394-1
SUSE-SU-2026:3482-1

Affected Products

Netty