Executive brief
Netty is a networking framework widely used in Java applications to handle HTTP and other network protocols. A vulnerability in its HTTP/2 implementation allows a remote attacker to trigger excessive memory and CPU consumption by sending specially crafted HTTP/2 frames, causing the application to become unresponsive or crash. This can disrupt services that depend on Netty for network communication.
Technical details
The vulnerability exists in Netty's HpackEncoder component within the HTTP/2 protocol handler. An attacker can send HTTP/2 SETTINGS frames with an extremely large MAX_HEADER_TABLE_SIZE value, which causes the encoder to allocate and store excessive memory for header tables. This triggers uncontrolled resource consumption (CPU and memory), leading to a Denial of Service condition. The attack is remotely exploitable over the network without authentication or user interaction required. No patch status is indicated in the available advisory text.
Affected products
- Netty Netty <UNKNOWN>
Timeline
- 2026-09-18: disclosed