PT-2026-99326 · Netty · Netty

CVE-2026-100655

·

Published

2026-09-26

·

Updated

2026-09-27

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Netty (io.netty:netty-codec-http) versions prior to 4.1.138.Final Netty (io.netty:netty-codec-http) versions 4.2.0.Final through 4.2.17.Final
Description The software accepts an unlimited number of concurrent remote-initiated SPDY streams because the SpdySessionHandler defaults localConcurrentStreams to Integer.MAX VALUE and provides no API to modify this value. A remote peer can exploit this by opening a SPDY connection and sending a massive volume of SYN STREAM frames with FLAG FIN=0, forcing the server to allocate unbounded heap and direct memory. This leads to a JVM OutOfMemoryError, which crashes the service.
Recommendations Update to version 4.1.138.Final. Update to version 4.2.18.Final.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100655
GHSA-RMCW-9FCQ-WJQ7

Affected Products

Netty