PT-2026-48688 · Maven · Io.Netty:Netty-Codec-Http2

Published

2026-06-11

·

Updated

2026-06-11

·

CVE-2026-48043

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Impact

The DelegatingDecompressorFrameListener class orchestrates HTTP/2 decompression by embedding a per-stream EmbeddedChannel that runs the appropriate decompression codec (gzip, deflate, zstd) and forwards decompressed chunks to a wrapped listener. Each decompressed chunk is a pooled ByteBuf handed to an anonymous ChannelInboundHandlerAdapter tail handler, which becomes the sole owner responsible for releasing it.
A remote peer could send frames that would result in the flow-controller throwing and so trigger a resource leak which at the end might take down the whole JVM due OOME.

Fix

Memory Leak

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2026-48043
GHSA-C2GF-V879-257J

Affected Products

Io.Netty:Netty-Codec-Http2