CVE-2026-56816
HIGH
7.5
CVSS 3.1
Description
Netty is a network application framework for development of protocol servers and clients. Prior to 4.2.16.Final, Netty's `Http3FrameCodec` buffers incoming data for HTTP/3 reserved frame types up to the wire-specified payload length without limits; `decodeFrame` trusts `payLoadLength`, allowing an attacker to open multiple QUIC streams and send reserved frames with very large payload lengths to cause memory exhaustion and denial of service. This issue is fixed in version 4.2.16.Final.
Metadata
Severity & Metrics
7.5
HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
SSVC — CISA Coordinator
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| netty | netty | — | < 4.2.16.Final |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-400 | cna | CWE-400: Uncontrolled Resource Consumption |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 7.5 | HIGH | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
References (3)
- https://github.com/netty/netty/security/advisories/GHSA-hpcc-26xq-25fv https://github.com/netty/netty/security/advisories/GHSA-hpcc-26xq-25fv
- https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b
- https://github.com/netty/netty/releases/tag/netty-4.2.16.Final https://github.com/netty/netty/releases/tag/netty-4.2.16.Final