PT-2026-61745 · Netty · Netty
CVE-2026-55833
·
Published
2026-07-20
·
Updated
2026-07-21
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Netty versions prior to 4.1.136.Final
Netty versions prior to 4.2.16.Final
Description
An issue exists in the SPDY header decoding process where the system continues inflating zlib-compressed header blocks even after the raw header parser has exceeded the
maxHeaderSize and marked the frame as truncated in SpdyFrameCodec. This allows a remote peer to send a small compressed HEADERS block that expands into significantly larger raw header data, leading to compression-amplified CPU and allocation churn, which can result in a Denial of Service.Recommendations
Update to version 4.1.136.Final.
Update to version 4.2.16.Final.
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netty