Executive brief
Netty is a widely-used networking library for building scalable Java applications. A flaw in its SMTP response decoder allows a malicious SMTP server to send specially crafted messages that consume unlimited memory on the client, eventually crashing the application with an out-of-memory error and causing service denial.
Technical details
The SmtpResponseDecoder component fails to bound memory allocation when processing multi-line SMTP responses lacking proper terminators, allowing a remote attacker acting as an MITM or malicious SMTP server to trigger unbounded memory accumulation in the JVM heap. This leads to OutOfMemoryError and denial of service via process crash. The vulnerability requires network access to SMTP connections and no authentication.
Affected products
- Netty Project Netty
Timeline
- 2026-09-18: disclosed