Junglewise Threat Intelligence

Netty memory leak in DNS Record Decoder via malformed domain names

Severity: medium · CVSS 5.3 · Published 2026-07-24

Vendors: Netty, Netty Project.

Executive brief

Netty is a popular networking framework used by many Java applications to handle internet traffic. A flaw in how it processes DNS records allows an attacker to send specially crafted requests that cause the application to leak memory. Over time, this memory exhaustion can lead to a complete service outage or significant performance degradation.

Technical details

A memory leak exists in Netty's DNS record decoder due to improper resource management during exception handling. When parsing a DNS record, the `AbstractDnsRecord` constructor or `DnsCodecUtil#decompressDomainName` may allocate or retain a `ByteBuf`. If the domain name contains characters violating IDNA rules or contains a null byte, an `IllegalArgumentException` is thrown before the buffer is assigned to a field for later release. Because the exception bypasses the standard release logic, the memory remains allocated. An unauthenticated remote attacker can exploit this by sending a stream of malicious DNS packets, leading to cumulative memory exhaustion and eventual Denial of Service. The issue is fixed in versions 4.1.136.Final and 4.2.16.Final.

Affected products

  • Netty netty-codec-dns >= 4.2.0.Final, <= 4.2.15.Final; <= 4.1.135.Final

Timeline

  • 2026-07-23: disclosed
  • 2026-07-24: advisory: GitHub Advisory published

References

Related threats