Allocation of Resources Without Limits or Throttling in Netty - #VU148878
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in HttpServerCodec\'s methodOverflowQueue when processing pipelined HTTP/1.1 requests while responses remain unread. A remote attacker can pipeline a large number of requests and withhold reads from the connection to cause a denial of service.