Junglewise Threat Intelligence

CVE-2026-93491: Netty HttpServerCodec denial of service via HTTP request pipelining

CVE-2026-93491 · Severity: high · CVSS 7.5 · Published 2026-09-18

Technologies: Netty. Vendors: Netty.

Executive brief

Netty is a widely-used networking library that provides HTTP protocol handling for Java applications. A remote attacker can exploit an unbounded memory growth vulnerability in the HTTP/1.1 request handler by pipelining multiple requests while withholding reads, causing the server to exhaust available memory and crash, resulting in service unavailability.

Technical details

The vulnerability exists in Netty's HttpServerCodec HTTP/1.1 handler, which uses an internal methodOverflowQueue to buffer data during request pipelining. When an attacker sends multiple pipelined HTTP/1.1 requests on a single connection without triggering reads, the queue grows without bounds due to lack of size limits, causing unbounded heap memory consumption. No authentication is required; the attack is triggered by network-accessible HTTP services. A successful exploit leads to denial of service through memory exhaustion and process termination. Patches are expected to impose limits on the queue size.

Affected products

  • Netty Netty

Timeline

  • 2026-09-18: disclosed

References

Related threats