Executive brief
Netty is a widely used networking framework that helps developers build high-performance servers and clients. A flaw in how it handles compressed web traffic (HTTP/2) allows a remote attacker to trigger a memory leak. If exploited, this can cause the application to run out of memory and crash, leading to a complete service outage.
Technical details
A memory leak exists in the `DelegatingDecompressorFrameListener` class within the `netty-codec-http2` module. The component manages HTTP/2 decompression (gzip, deflate, zstd) using an `EmbeddedChannel` where decompressed `ByteBuf` chunks are owned by a tail handler. An attacker can send specifically crafted frames that cause the flow-controller to throw an exception, bypassing the standard release mechanism for these pooled buffers. This results in a reference-count leak that accumulates over time, eventually causing the JVM to crash with an OutOfMemoryError (OOME). The issue is fixed in versions 4.1.135.Final and 4.2.15.Final.
Affected products
- Netty netty-codec-http2 < 4.1.135.Final, < 4.2.15.Final
Timeline
- 2026-06-02: patched: Versions 4.1.135.Final and 4.2.15.Final released
- 2026-06-05: advisory: GitHub Security Advisory published
- 2026-06-12: disclosed: CVE published to NVD