Executive brief
Netty is a Java networking library used to build high-performance servers and network applications. The SPDY protocol handler fails to limit the number of concurrent streams a remote peer can initiate, allowing an attacker to exhaust server memory by opening millions of streams, which crashes the service.
Technical details
SpdySessionHandler defaults localConcurrentStreams to Integer.MAX_VALUE with no API to configure it. A remote attacker can send numerous SYN_STREAM frames with FLAG_FIN=0 over a SPDY connection, causing unbounded allocation of heap and direct memory until JVM OutOfMemoryError occurs. The vulnerability requires network access and affects versions 4.1.137.Final and earlier, and 4.2.0.Final through 4.2.17.Final; patches are available in 4.1.138.Final and 4.2.18.Final.
Affected products
- Netty netty-codec-http up to 4.1.137.Final and 4.2.0.Final through 4.2.17.Final
Timeline
- 2026-09-26: disclosed
- 2026-09-26: patched: Patched in 4.1.138.Final and 4.2.18.Final