Junglewise Threat Intelligence

CVE-2026-55831: Netty resource exhaustion in SPDY SETTINGS decoder

CVE-2026-55831 · Severity: high · CVSS 7.5 · Published 2026-07-21

Technologies: Netty-Codec-Http, Netty Project Codec HTTP. Vendors: Netty, Netty Project.

Executive brief

Netty is a popular networking framework used by many Java-based applications to handle web traffic. A vulnerability in its SPDY protocol implementation allows a remote attacker to crash or slow down a server by sending a specially crafted message. This can lead to a denial-of-service (DoS) condition, making the affected service unavailable to legitimate users.

Technical details

An uncontrolled resource consumption vulnerability (CWE-400) exists in Netty's SpdyFrameCodec. The SPDY SETTINGS decoder accepts a peer-declared entry count up to the 24-bit frame-length limit without an implementation-level cap. When a crafted frame is received, DefaultSpdySettingsFrame materializes every unique setting ID into a TreeMap. A remote, unauthenticated attacker can send a ~2 MiB frame containing 262,144 entries, causing significant heap growth and CPU consumption due to map insertion work. This can be exploited to trigger a denial-of-service (DoS) via memory exhaustion. The issue is patched in versions 4.1.136.Final and 4.2.16.Final.

Affected products

  • Netty netty-codec-http >= 4.1.0.Final, <= 4.1.135.Final
  • Netty netty-codec-http >= 4.2.0.Final, <= 4.2.15.Final

Timeline

  • 2026-07-14: disclosed: Initial disclosure in Netty repository
  • 2026-07-21: advisory: NVD publication date
  • 2026-07-22: advisory: GitHub Advisory Database publication date

References

Related threats