Allocation of Resources Without Limits or Throttling in Netty - CVE-2026-33871
Published: March 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to allocation of resources without limits or throttling in the "DefaultHttp2FrameReader" function within HTTP/2 server. A remote attacker can send a flood of CONTINUATION frames and cause a denial of service condition on the target system.
Affected software
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Development Tools Module
SUSE Package Hub 15
openSUSE Leap
IBM SPSS Analytic Server
IBM Decision Optimization for Cloud Pak for Data
IBM Watson Discovery for IBM Cloud Pak for Data
Jira Service Management Data Center
IBM Sterling Partner Engagement Manager
Confluence Data Center
Bitbucket Data Center
Jira Software Data Center
Bamboo Data Center
DataStage on Cloud Pak for Data
IBM DB2
netty-tcnative-javadoc
netty-tcnative-debugsource
netty-tcnative
netty
netty-javadoc
JBoss Data Grid
How to mitigate CVE-2026-33871
IBM Decision Optimization for Cloud Pak for Data - update to 5.3.1 patch 4
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.2
DataStage on Cloud Pak for Data - update to 5.4
Jira Service Management Data Center - addressed in versions 10.3.22, 11.3.5
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.6, 6.2.4.4
Confluence Data Center - addressed in versions 9.2.19, 10.2.10
Bitbucket Data Center - addressed in versions 9.4.22, 10.2.4, 10.3.1
Jira Software Data Center - addressed in versions 9.12.28, 10.3.22, 11.3.5
Bamboo Data Center - addressed in versions 10.2.18, 12.1.6
netty-tcnative-javadoc - update to 2.0.75-150200.3.36.1
netty-tcnative-debugsource - update to 2.0.75-150200.3.36.1
netty-tcnative - update to 2.0.75-150200.3.36.1
netty - update to 4.1.132-150200.4.43.1
netty-javadoc - update to 4.1.132-150200.4.43.1
JBoss Data Grid - update to 8.6.1
External References
Related Security Bulletins
- Multiple vulnerabilities in Netty
- SUSE update for netty, netty-tcnative
- Bamboo Data Center update for netty-codec-http2 DoS
- Confluence Data Center update for netty-codec-http2
- IBM Watson Discovery Cartridge update for Netty
- Multiple vulnerabilities in IBM SPSS Analytic Server
- Multiple vulnerabilities in IBM Decision Optimization for Cloud Pak for Data
- Multiple vulnerabilities in JBoss Data Grid 8.6
- Multiple vulnerabilities in Jira Service Management Data Center and Jira Service Management Server
- Multiple vulnerabilities in Jira Software Data Center
- Multiple vulnerabilities in IBM DataStage on Cloud Pak for Data
- Multiple vulnerabilities in IBM Db2
- Multiple vulnerabilities in IBM Sterling Partner Engagement Manager
- Multiple vulnerabilities in Bitbucket Data Center