Allocation of Resources Without Limits or Throttling in Netty - CVE-2026-33871

 

Allocation of Resources Without Limits or Throttling in Netty - CVE-2026-33871

Published: March 25, 2026


Vulnerability identifier: #VU124423
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-33871
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to allocation of resources without limits or throttling in the "DefaultHttp2FrameReader" function within HTTP/2 server. A remote attacker can send a flood of CONTINUATION frames and cause a denial of service condition on the target system.


Affected software

Netty
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Development Tools Module
SUSE Package Hub 15
openSUSE Leap
IBM SPSS Analytic Server
IBM Decision Optimization for Cloud Pak for Data
IBM Watson Discovery for IBM Cloud Pak for Data
Jira Service Management Data Center
IBM Sterling Partner Engagement Manager
Confluence Data Center
Bitbucket Data Center
Jira Software Data Center
Bamboo Data Center
DataStage on Cloud Pak for Data
IBM DB2
netty-tcnative-javadoc
netty-tcnative-debugsource
netty-tcnative
netty
netty-javadoc
JBoss Data Grid

How to mitigate CVE-2026-33871

Install updates from vendor's website.

Netty - addressed in versions 4.1.132, 4.2.11
IBM Decision Optimization for Cloud Pak for Data - update to 5.3.1 patch 4
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.2
DataStage on Cloud Pak for Data - update to 5.4
Jira Service Management Data Center - addressed in versions 10.3.22, 11.3.5
IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.6, 6.2.4.4
Confluence Data Center - addressed in versions 9.2.19, 10.2.10
Bitbucket Data Center - addressed in versions 9.4.22, 10.2.4, 10.3.1
Jira Software Data Center - addressed in versions 9.12.28, 10.3.22, 11.3.5
Bamboo Data Center - addressed in versions 10.2.18, 12.1.6
netty-tcnative-javadoc - update to 2.0.75-150200.3.36.1
netty-tcnative-debugsource - update to 2.0.75-150200.3.36.1
netty-tcnative - update to 2.0.75-150200.3.36.1
netty - update to 4.1.132-150200.4.43.1
netty-javadoc - update to 4.1.132-150200.4.43.1
JBoss Data Grid - update to 8.6.1

External References

Related Security Bulletins