PT-2026-99329 · Netty · Netty
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Netty (io.netty:netty-codec-http) versions 4.1.88.Final through 4.1.137.Final
Netty (io.netty:netty-codec-http) versions 4.2.0.Final through 4.2.17.Final
Description
An unbounded per-connection queue exists in the
WebSocketServerExtensionHandler. The handler adds an entry to its validExtensions queue for every inbound HttpRequest but only removes an entry when the application writes an HttpResponse. A remote, unauthenticated attacker can utilize HTTP/1.1 pipelining—a technique where multiple requests are sent over a single TCP connection without waiting for the corresponding responses—to send requests faster than the application can respond. This causes the queue to grow indefinitely, leading to JVM heap memory exhaustion and an OutOfMemoryError. Since this handler is the base class for WebSocketServerCompressionHandler, servers enabling permessage-deflate are exposed on their plain HTTP port before WebSocket upgrades or application-level authentication occur.Recommendations
Update to version 4.1.138.Final or later.
Update to version 4.2.18.Final or later.
Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netty