Junglewise Threat Intelligence

CVE-2026-59901: Netty Bzip2Decoder infinite loop denial of service

CVE-2026-59901 · Severity: high · CVSS 4 · Published 2026-07-29

Technologies: io.netty:netty-codec (Maven), io.netty:netty-codec-compression (Maven). Vendors: Maven, Netty.

Executive brief

Netty, a widely used framework for building high-performance network applications, contains a flaw in how it handles compressed data. An attacker can send a specially crafted data stream that forces the application into an infinite loop, effectively freezing the service. This results in a denial-of-service, making the application unresponsive to legitimate users and potentially impacting business operations.

Technical details

A vulnerability exists in the Bzip2Decoder handler within Netty's compression codec pipeline. The flaw is located in the run-length encoding (RLE) state machine within the Bzip2BlockDecompressor.read() method. By providing a malformed bzip2 stream, a remote unauthenticated attacker can trigger an infinite loop (CWE-835) that permanently captures the event-loop thread. Because Netty relies on a non-blocking event-driven model, hanging an event-loop thread can lead to a complete denial of service for all connections handled by that thread. The issue is resolved in versions 4.1.136.Final and 4.2.16.Final.

Affected products

  • Netty netty-codec < 4.1.136.Final
  • Netty netty-codec-compression >= 4.2.0.Final, < 4.2.16.Final

Timeline

  • 2026-07-14: advisory: GitHub Security Advisory published
  • 2026-07-29: disclosed: NVD publication date

References

Related threats