Junglewise Threat Intelligence

CVE-2026-56745: Netty memory leak in SpdyHttpDecoder leading to DoS

CVE-2026-56745 · Severity: high · CVSS 4 · Published 2026-07-21

Technologies: Netty-Codec-Http, Netty Project Codec HTTP. Vendors: Netty, Netty Project.

Executive brief

Netty is a popular networking framework used by many Java-based applications to handle web traffic. A flaw in its SPDY protocol component allows a remote attacker to cause the application to leak memory by sending specific sequences of network messages. Over time, this memory leak can exhaust the server's available resources, leading to a complete service outage or application crash.

Technical details

A memory leak exists in the SpdyHttpDecoder handler within Netty's SPDY-to-HTTP codec. When processing a client-initiated SYN_STREAM frame with FLAG_FIN=0, the decoder allocates a pooled ByteBuf and stores a partially-constructed FullHttpRequest in an internal messageMap. If the remote peer subsequently sends an RST_STREAM frame or if the accumulated content exceeds the maxContentLength, the decoder removes the entry from the map but fails to call release() on the pooled ByteBuf. This results in a permanent leak of native memory. An unauthenticated remote attacker can exploit this by repeatedly initiating and then resetting streams, eventually causing an OutOfMemoryError (OOME) and denial of service. The issue is fixed in versions 4.1.136.Final and 4.2.16.Final.

Affected products

  • Netty netty-codec-http >= 4.1.0.Final, <= 4.1.135.Final
  • Netty netty-codec-http >= 4.2.0.Final, <= 4.2.15.Final

Timeline

  • 2026-07-14: disclosed: Advisory published by maintainers
  • 2026-07-21: advisory: NVD published CVE-2026-56745
  • 2026-07-22: patched: GitHub Advisory Database entry finalized

References

Related threats