PT-2026-61744 · Netty · Netty
CVE-2026-55831
·
Published
2026-07-20
·
Updated
2026-07-21
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Netty versions prior to 4.1.136.Final
Netty versions prior to 4.2.16.Final
Description
The SPDY SETTINGS decoder in Netty allows a remote SPDY/3.1 peer to send a syntactically valid SETTINGS frame of approximately 2 MiB. This frame can contain a peer-declared SETTINGS entry count up to the 24-bit frame-length limit, which the
DefaultSpdySettingsFrame then materializes for every unique setting ID. This process amplifies network input into significant heap growth and ordered-map insertion work, potentially leading to a denial of service.Recommendations
Update to version 4.1.136.Final or later.
Update to version 4.2.16.Final or later.
Fix
DoS
Allocation of Resources Without Limits
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Netty