SB2026091030 - Multiple vulnerabilities in Netty
Published: September 10, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 10 vulnerabilities.
1) Allocation of Resources Without Limits or Throttling (CVE-ID: N/A)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in SpdySessionHandler when processing remote-initiated SYN_STREAM frames. A remote attacker can send millions of SYN_STREAM frames with FLAG_FIN=0 to cause a denial of service.
2) Allocation of Resources Without Limits or Throttling (CVE-ID: N/A)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in HttpServerCodec\'s methodOverflowQueue when processing pipelined HTTP/1.1 requests while responses remain unread. A remote attacker can pipeline a large number of requests and withhold reads from the connection to cause a denial of service.
3) Resource exhaustion (CVE-ID: N/A)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the HTTP/2 HpackEncoder when processing SETTINGS frames with a very large MAX_HEADER_TABLE_SIZE value. A remote attacker can send a SETTINGS frame with a large MAX_HEADER_TABLE_SIZE value to cause a denial of service.
The HPACK table is scoped to a connection.
4) Improper Check for Certificate Revocation (CVE-ID: N/A)
CWE-ID: CWE-299 - Improper Check for Certificate Revocation
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass certificate revocation validation.
The vulnerability exists due to an improper check for certificate revocation in OcspServerCertificateValidator when processing an OCSP response that omits the optional nextUpdate field. A remote attacker can supply a crafted OCSP response to bypass certificate revocation validation.
Nonce validation is disabled by default.
5) Missing Release of Resource after Effective Lifetime (CVE-ID: N/A)
CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to missing release of a resource after its effective lifetime in StompSubframeDecoder when processing a STOMP frame body without its terminating NUL byte. A remote attacker can send a complete STOMP frame body while omitting its terminating byte to cause a denial of service.
6) Resource exhaustion (CVE-ID: N/A)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in WebSocketServerExtensionHandler when processing HTTP/1.1 pipelined requests faster than the application produces responses. A remote attacker can send a sustained stream of pipelined HTTP requests while keeping connections open to cause a denial of service.
The queue is populated for every HTTP request, including non-WebSocket-upgrade requests, and remains allocated for the lifetime of the connection.
7) Inconsistent interpretation of HTTP requests (CVE-ID: N/A)
CWE-ID: CWE-444 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass routing and access-control decisions based on the request authority.
The vulnerability exists due to inconsistent interpretation of HTTP requests in Netty\'s HTTP/3 codec when processing a HEADERS frame containing conflicting :authority and host header values. A remote attacker can send a crafted HEADERS frame with differing authority values to bypass routing and access-control decisions based on the request authority.
Different components in the request path may consult different authority fields.
8) Incorrect Conversion between Numeric Types (CVE-ID: N/A)
CWE-ID: CWE-681 - Incorrect Conversion between Numeric Types
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to incorrect conversion between numeric types in StompSubframeDecoder.java when processing STOMP frames with a content-length value exceeding the maximum integer value. A remote attacker can send a specially crafted STOMP frame to cause a denial of service.
Default configurations are affected.
9) Signed to Unsigned Conversion Error (CVE-ID: N/A)
CWE-ID: CWE-195 - Signed to Unsigned Conversion Error
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose response data to other clients.
The vulnerability exists due to a signed to unsigned conversion error in the memcache binary protocol codec when processing crafted memcache responses. A remote attacker can send a specially crafted memcache response to disclose response data to other clients.
The issue can desynchronize frame boundaries in proxy or cache scenarios.
10) Allocation of Resources Without Limits or Throttling (CVE-ID: N/A)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the QpackEncoder streamSectionTrackers map when processing HTTP/3 response field sections while a peer withholds Section Acknowledgments. A remote attacker can sequentially complete requests and omit Section Acknowledgments to cause a denial of service.
The server must emit at least one repeatable, non-sensitive response header eligible for QPACK dynamic indexing.
Remediation
Install update from vendor's website.
References
- https://github.com/netty/netty/security/advisories/GHSA-rmcw-9fcq-wjq7
- https://github.com/netty/netty/security/advisories/GHSA-pvjx-v7vp-62vq
- https://github.com/netty/netty/security/advisories/GHSA-8352-h356-c9qh
- https://github.com/netty/netty/security/advisories/GHSA-jj3c-mwvr-9g52
- https://github.com/netty/netty/security/advisories/GHSA-ghg5-c4jg-8q5j
- https://github.com/netty/netty/security/advisories/GHSA-2g37-3h88-55hc
- https://github.com/netty/netty/security/advisories/GHSA-q9pg-8h3j-8hvm
- https://github.com/netty/netty/security/advisories/GHSA-hmf3-49g9-g7qq
- https://github.com/netty/netty/security/advisories/GHSA-wxrh-4rgq-pjcg
- https://github.com/netty/netty/security/advisories/GHSA-495p-pchh-r4mc