Junglewise Threat Intelligence

CVE-2026-100655: Netty netty-codec-http denial of service in SpdySessionHandler

CVE-2026-100655 · Severity: high · CVSS 7.5 · Published 2026-09-26

Technologies: Netty-Codec-Http. Vendors: Netty.

Executive brief

Netty is a Java networking library used to build high-performance servers and network applications. The SPDY protocol handler fails to limit the number of concurrent streams a remote peer can initiate, allowing an attacker to exhaust server memory by opening millions of streams, which crashes the service.

Technical details

SpdySessionHandler defaults localConcurrentStreams to Integer.MAX_VALUE with no API to configure it. A remote attacker can send numerous SYN_STREAM frames with FLAG_FIN=0 over a SPDY connection, causing unbounded allocation of heap and direct memory until JVM OutOfMemoryError occurs. The vulnerability requires network access and affects versions 4.1.137.Final and earlier, and 4.2.0.Final through 4.2.17.Final; patches are available in 4.1.138.Final and 4.2.18.Final.

Affected products

  • Netty netty-codec-http up to 4.1.137.Final and 4.2.0.Final through 4.2.17.Final

Timeline

  • 2026-09-26: disclosed
  • 2026-09-26: patched: Patched in 4.1.138.Final and 4.2.18.Final

References

Related threats