PT-2026-61744 · Netty · Netty

CVE-2026-55831

·

Published

2026-07-20

·

Updated

2026-07-21

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Netty versions prior to 4.1.136.Final Netty versions prior to 4.2.16.Final
Description The SPDY SETTINGS decoder in Netty allows a remote SPDY/3.1 peer to send a syntactically valid SETTINGS frame of approximately 2 MiB. This frame can contain a peer-declared SETTINGS entry count up to the 24-bit frame-length limit, which the DefaultSpdySettingsFrame then materializes for every unique setting ID. This process amplifies network input into significant heap growth and ordered-map insertion work, potentially leading to a denial of service.
Recommendations Update to version 4.1.136.Final or later. Update to version 4.2.16.Final or later.

Fix

DoS

Allocation of Resources Without Limits

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55831

Affected Products

Netty