Junglewise Threat Intelligence

CVE-2026-48043: Netty memory exhaustion in DelegatingDecompressorFrameListener

CVE-2026-48043 · Severity: medium · CVSS 5.3 · Published 2026-06-12

Technologies: Netty Project Netty Codec HTTP2. Vendors: Netty, Netty Project.

Executive brief

Netty is a widely used networking framework that helps developers build high-performance servers and clients. A flaw in how it handles compressed web traffic (HTTP/2) allows a remote attacker to trigger a memory leak. If exploited, this can cause the application to run out of memory and crash, leading to a complete service outage.

Technical details

A memory leak exists in the `DelegatingDecompressorFrameListener` class within the `netty-codec-http2` module. The component manages HTTP/2 decompression (gzip, deflate, zstd) using an `EmbeddedChannel` where decompressed `ByteBuf` chunks are owned by a tail handler. An attacker can send specifically crafted frames that cause the flow-controller to throw an exception, bypassing the standard release mechanism for these pooled buffers. This results in a reference-count leak that accumulates over time, eventually causing the JVM to crash with an OutOfMemoryError (OOME). The issue is fixed in versions 4.1.135.Final and 4.2.15.Final.

Affected products

  • Netty netty-codec-http2 < 4.1.135.Final, < 4.2.15.Final

Timeline

  • 2026-06-02: patched: Versions 4.1.135.Final and 4.2.15.Final released
  • 2026-06-05: advisory: GitHub Security Advisory published
  • 2026-06-12: disclosed: CVE published to NVD

References

Related threats