Executive brief
Netty is a popular networking framework used by many Java-based applications to handle web traffic. A vulnerability in its SPDY protocol implementation allows a remote attacker to crash or slow down a server by sending a specially crafted message. This can lead to a denial-of-service (DoS) condition, making the affected service unavailable to legitimate users.
Technical details
An uncontrolled resource consumption vulnerability (CWE-400) exists in Netty's SpdyFrameCodec. The SPDY SETTINGS decoder accepts a peer-declared entry count up to the 24-bit frame-length limit without an implementation-level cap. When a crafted frame is received, DefaultSpdySettingsFrame materializes every unique setting ID into a TreeMap. A remote, unauthenticated attacker can send a ~2 MiB frame containing 262,144 entries, causing significant heap growth and CPU consumption due to map insertion work. This can be exploited to trigger a denial-of-service (DoS) via memory exhaustion. The issue is patched in versions 4.1.136.Final and 4.2.16.Final.
Affected products
- Netty netty-codec-http >= 4.1.0.Final, <= 4.1.135.Final
- Netty netty-codec-http >= 4.2.0.Final, <= 4.2.15.Final
Timeline
- 2026-07-14: disclosed: Initial disclosure in Netty repository
- 2026-07-21: advisory: NVD publication date
- 2026-07-22: advisory: GitHub Advisory Database publication date