PT-2026-99327 · Netty · Netty
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Netty (io.netty:netty-codec-http) versions 4.2.0.Final through 4.2.17.Final
Netty (io.netty:netty-codec-http) versions prior to 4.1.138.Final
Description
An unbounded per-connection queue growth flaw exists in the
HttpServerCodec. The codec tracks the HTTP method of unanswered pipelined requests; while the first 32 entries are bit-packed into a single long, subsequent entries are added to the methodOverflowQueue (an ArrayDeque with no size limit or rejection path). A remote, unauthenticated attacker can exploit this by pipelining HTTP/1.1 requests on a single connection and withholding reads to prevent responses from being flushed. This action allows the queue to grow without bound, leading to unbounded heap growth and a denial of service.Recommendations
Update to version 4.2.18.Final.
Update to version 4.1.138.Final.
Exploit
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netty