PT-2026-99327 · Netty · Netty

·

CVE-2026-100656

·

Published

2026-09-26

·

Updated

2026-09-27

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Netty (io.netty:netty-codec-http) versions 4.2.0.Final through 4.2.17.Final Netty (io.netty:netty-codec-http) versions prior to 4.1.138.Final
Description An unbounded per-connection queue growth flaw exists in the HttpServerCodec. The codec tracks the HTTP method of unanswered pipelined requests; while the first 32 entries are bit-packed into a single long, subsequent entries are added to the methodOverflowQueue (an ArrayDeque with no size limit or rejection path). A remote, unauthenticated attacker can exploit this by pipelining HTTP/1.1 requests on a single connection and withholding reads to prevent responses from being flushed. This action allows the queue to grow without bound, leading to unbounded heap growth and a denial of service.
Recommendations Update to version 4.2.18.Final. Update to version 4.1.138.Final.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100656
GHSA-PVJX-V7VP-62VQ

Affected Products

Netty