Executive brief
Netty, a widely used framework for building high-performance network applications, contains a flaw in how it handles compressed data. An attacker can send a specially crafted data stream that forces the application into an infinite loop, effectively freezing the service. This results in a denial-of-service, making the application unresponsive to legitimate users and potentially impacting business operations.
Technical details
A vulnerability exists in the Bzip2Decoder handler within Netty's compression codec pipeline. The flaw is located in the run-length encoding (RLE) state machine within the Bzip2BlockDecompressor.read() method. By providing a malformed bzip2 stream, a remote unauthenticated attacker can trigger an infinite loop (CWE-835) that permanently captures the event-loop thread. Because Netty relies on a non-blocking event-driven model, hanging an event-loop thread can lead to a complete denial of service for all connections handled by that thread. The issue is resolved in versions 4.1.136.Final and 4.2.16.Final.
Affected products
- Netty netty-codec < 4.1.136.Final
- Netty netty-codec-compression >= 4.2.0.Final, < 4.2.16.Final
Timeline
- 2026-07-14: advisory: GitHub Security Advisory published
- 2026-07-29: disclosed: NVD publication date