PT-2026-99332 · Unknown · Netty-Codec-Http3
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
netty-codec-http3 versions 4.2.0.Final through 4.2.17.Final
Description
A denial-of-service issue exists in the QPACK prefixed-integer decoder
QpackUtil.decodePrefixedInteger() that fails to bound the number of continuation bytes processed. A remote, unauthenticated peer can open a QPACK unidirectional stream and send a first byte with all prefix bits set, followed by a continuous sequence of 0x80 continuation bytes. This causes the ByteToMessageDecoder cumulator to grow without bound and forces each decode() call to re-scan the entire accumulated buffer, resulting in O(N^2) CPU cost. This leads to event-loop CPU starvation and unbounded per-connection heap growth, potentially causing an OutOfMemoryError across all configurations.Recommendations
Update to version 4.2.18.Final.
Exploit
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netty-Codec-Http3