PT-2026-63549 · Maven · Io.Netty:Netty-Codec+1

CVE-2026-59901

·

Published

2026-07-22

·

Updated

2026-07-22

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
The Bzip2Decoder handler in Netty's compression codec pipeline is vulnerable to a denial-of-service attack through a malformed bzip2 stream that permanently captures the event-loop thread in an infinite loop. The vulnerability exists in the run-length encoding (RLE) state machine within [Bzip2BlockDecompressor.read()]

Fix

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59901
GHSA-558V-64GR-WGG4

Affected Products

Io.Netty:Netty-Codec
Io.Netty:Netty-Codec-Compression