Junglewise Threat Intelligence

CVE-2026-100656: Netty HttpServerCodec unbounded queue growth via HTTP/1.1 pipelining

CVE-2026-100656 · Severity: high · CVSS 7.5 · Published 2026-09-26

Technologies: Netty-Codec-Http. Vendors: Netty.

Executive brief

Netty is a widely-used Java networking library that powers HTTP/1.1 servers. An unauthenticated attacker can exploit the HttpServerCodec component by sending pipelined HTTP requests while deliberately blocking responses, causing the server to accumulate an unbounded in-memory queue that exhausts heap memory and crashes the service.

Technical details

The HttpServerCodec class tracks pending HTTP request methods using a bit-packed long (32 entries) plus an unbounded ArrayDeque (methodOverflowQueue) for overflow. The enqueueMethod() function adds entries unconditionally without size limits. An attacker sending pipelined requests on one connection while withholding read operations (preventing response flush) forces the decoder to run ahead, filling the overflow queue without bound. Remote, unauthenticated, network-only attack; patches are available in 4.2.18.Final and 4.1.138.Final.

Affected products

  • Netty netty-codec-http 4.2.0.Final through 4.2.17.Final, 4.1.0.Final through 4.1.137.Final

Timeline

  • 2026-09-26: disclosed
  • 2026-09-26: patched: 4.2.18.Final and 4.1.138.Final released

References

Related threats