Junglewise Threat Intelligence

CVE-2026-93563: Netty SmtpResponseDecoder unbounded memory accumulation

CVE-2026-93563 · Severity: high · CVSS 7.5 · Published 2026-09-18

Technologies: Netty Project Netty. Vendors: Netty Project.

Executive brief

Netty is a widely-used networking library for building scalable Java applications. A flaw in its SMTP response decoder allows a malicious SMTP server to send specially crafted messages that consume unlimited memory on the client, eventually crashing the application with an out-of-memory error and causing service denial.

Technical details

The SmtpResponseDecoder component fails to bound memory allocation when processing multi-line SMTP responses lacking proper terminators, allowing a remote attacker acting as an MITM or malicious SMTP server to trigger unbounded memory accumulation in the JVM heap. This leads to OutOfMemoryError and denial of service via process crash. The vulnerability requires network access to SMTP connections and no authentication.

Affected products

  • Netty Project Netty

Timeline

  • 2026-09-18: disclosed

References

Related threats