PT-2026-38360 · Netty+2 · Netty+2

CVE-2026-42583

·

Published

2026-05-05

·

Updated

2026-07-21

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Netty (affected versions not specified)
Description A resource exhaustion issue exists in the decode() function of the io.netty.handler.codec.compression.Lz4FrameDecoder class. The decoder trusts header fields to determine buffer sizing, specifically allocating a ByteBuf based on the decompressedLength variable (which can reach up to 32 MB per block) before the LZ4 decompression process begins. An attacker can trigger this large allocation by sending a small payload consisting of a 21-byte header plus compressedLength payload bytes. This allows untrusted senders to stress system memory by sending numerous small requests if per-channel or aggregate limits are not implemented.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Allocation of Resources Without Limits

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09787
CLEANSTART-2026-AB08507
CLEANSTART-2026-AO11810
CLEANSTART-2026-AO61361
CLEANSTART-2026-CP46043
CLEANSTART-2026-DD05788
CLEANSTART-2026-DT81884
CLEANSTART-2026-DU71732
CLEANSTART-2026-DW56632
CLEANSTART-2026-EG39405
CLEANSTART-2026-FE86476
CLEANSTART-2026-GI91246
CLEANSTART-2026-GX01236
CLEANSTART-2026-GX44743
CLEANSTART-2026-IY44515
CLEANSTART-2026-JR82778
CLEANSTART-2026-KB52131
CLEANSTART-2026-LB01734
CLEANSTART-2026-LE11246
CLEANSTART-2026-LZ76508
CLEANSTART-2026-MT41286
CLEANSTART-2026-MX76059
CLEANSTART-2026-OF88781
CLEANSTART-2026-PO27799
CLEANSTART-2026-QT07988
CLEANSTART-2026-RD06185
CLEANSTART-2026-RN56220
CLEANSTART-2026-RU36468
CLEANSTART-2026-SP91806
CLEANSTART-2026-TX47991
CLEANSTART-2026-UY99208
CLEANSTART-2026-VG64236
CLEANSTART-2026-VJ37814
CLEANSTART-2026-WA05811
CLEANSTART-2026-WK99982
CLEANSTART-2026-XS55749
CLEANSTART-2026-YM13650
CLEANSTART-2026-YP34235
CLEANSTART-2026-YX16662
CLEANSTART-2026-ZJ03849
CVE-2026-42583
GHSA-MJ4R-2HFC-F8P6
OPENSUSE-SU-2026:10795-1
SUSE-SU-2026:2308-1

Affected Products

Confluence
Netty
Red Os