Executive brief
Netty is a widely used networking framework that helps Java applications communicate over the internet. A flaw in how it handles compressed data allows a remote attacker to force the application to allocate large amounts of memory using very small requests. This can lead to a denial-of-service (DoS) condition where the application crashes or becomes unresponsive due to memory exhaustion.
Technical details
The Lz4FrameDecoder in Netty fails to properly validate the 'decompressedLength' field in LZ4 frame headers before allocating memory. An attacker can send a specially crafted 21-byte header that specifies a large decompression size (up to 32 MB), forcing the decoder to allocate a ByteBuf of that size before the actual decompression occurs. By sending multiple such small requests, a remote, unauthenticated attacker can exhaust the heap memory of the application. This vulnerability affects the io.netty:netty-codec and io.netty:netty-codec-compression packages and is fixed in versions 4.1.133.Final and 4.2.13.Final.
Affected products
- Netty netty-codec <= 4.1.132.Final
- Netty netty-codec-compression <= 4.2.12.Final
Timeline
- 2026-05-05: advisory: GitHub Security Advisory published
- 2026-05-13: disclosed: CVE published to NVD