Allocation of Resources Without Limits or Throttling in Netty - #VU148886
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the QpackEncoder streamSectionTrackers map when processing HTTP/3 response field sections while a peer withholds Section Acknowledgments. A remote attacker can sequentially complete requests and omit Section Acknowledgments to cause a denial of service.
The server must emit at least one repeatable, non-sensitive response header eligible for QPACK dynamic indexing.