Executive brief
Netty is a widely-used networking library that provides HTTP protocol handling for Java applications. A remote attacker can exploit an unbounded memory growth vulnerability in the HTTP/1.1 request handler by pipelining multiple requests while withholding reads, causing the server to exhaust available memory and crash, resulting in service unavailability.
Technical details
The vulnerability exists in Netty's HttpServerCodec HTTP/1.1 handler, which uses an internal methodOverflowQueue to buffer data during request pipelining. When an attacker sends multiple pipelined HTTP/1.1 requests on a single connection without triggering reads, the queue grows without bounds due to lack of size limits, causing unbounded heap memory consumption. No authentication is required; the attack is triggered by network-accessible HTTP services. A successful exploit leads to denial of service through memory exhaustion and process termination. Patches are expected to impose limits on the queue size.
Affected products
- Netty Netty
Timeline
- 2026-09-18: disclosed