Allocation of Resources Without Limits or Throttling in Netty - #VU148877
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in SpdySessionHandler when processing remote-initiated SYN_STREAM frames. A remote attacker can send millions of SYN_STREAM frames with FLAG_FIN=0 to cause a denial of service.