Junglewise Threat Intelligence

CVE-2026-42583: Netty Lz4FrameDecoder resource exhaustion

CVE-2026-42583 · Severity: high · CVSS 7.5 · Published 2026-05-13

Technologies: io.netty:netty-codec (Maven), io.netty:netty-codec-compression (Maven). Vendors: Netty, Maven, Netty Project.

Executive brief

Netty is a widely used networking framework that helps Java applications communicate over the internet. A flaw in how it handles compressed data allows a remote attacker to force the application to allocate large amounts of memory using very small requests. This can lead to a denial-of-service (DoS) condition where the application crashes or becomes unresponsive due to memory exhaustion.

Technical details

The Lz4FrameDecoder in Netty fails to properly validate the 'decompressedLength' field in LZ4 frame headers before allocating memory. An attacker can send a specially crafted 21-byte header that specifies a large decompression size (up to 32 MB), forcing the decoder to allocate a ByteBuf of that size before the actual decompression occurs. By sending multiple such small requests, a remote, unauthenticated attacker can exhaust the heap memory of the application. This vulnerability affects the io.netty:netty-codec and io.netty:netty-codec-compression packages and is fixed in versions 4.1.133.Final and 4.2.13.Final.

Affected products

  • Netty netty-codec <= 4.1.132.Final
  • Netty netty-codec-compression <= 4.2.12.Final

Timeline

  • 2026-05-05: advisory: GitHub Security Advisory published
  • 2026-05-13: disclosed: CVE published to NVD

References

Related threats