Executive brief
Netty is a Java networking library used to build high-performance servers and client applications. A flaw in its WebSocket handler allows a remote attacker to send HTTP requests faster than the server responds, causing an unbounded queue to grow until the Java process runs out of memory and crashes, disrupting service. Any server using WebSocket compression or HTTP request handling is vulnerable, even before a WebSocket upgrade occurs.
Technical details
WebSocketServerExtensionHandler maintains an unbounded per-connection queue (validExtensions) that grows by one entry for every inbound HttpRequest but drains only when the application writes an HttpResponse. An attacker can exploit HTTP/1.1 pipelining to send requests faster than responses are generated, causing the queue to grow without limit and exhaust heap memory (OutOfMemoryError). The vulnerability is pre-authentication and affects all HTTP traffic on the port, not just WebSocket upgrades.
Affected products
- Netty netty-codec-http 4.1.88.Final through 4.1.137.Final, 4.2.0.Final through 4.2.17.Final
Timeline
- 2026-09-26: disclosed
- 2026-09-26: patched: Fixed in 4.1.138.Final and 4.2.18.Final