CVE-2026-93488 Denial of Service in Netty SpdySessionHandler
The Netty SpdySessionHandler component is vulnerable to a denial of service attack via uncontrolled concurrent stream allocation, potentially exhausting JVM heap and direct memory.
CVE search metadata
CVE search record: CVE-2026-93488. Severity: high. CVSS: 7.5. KEV: no. Product: Netty (all versions). Brief: CVE-2026-93488 Denial of Service in Netty SpdySessionHandler. Brief link: https://feed.craftedsignal.io/briefs/2026-09-netty-dos/
CVE-2026-93488 is a high-severity vulnerability discovered in the Netty framework's SPDY implementation. The SpdySessionHandler fails to restrict the number of concurrent remote-initiated streams because the localConcurrentStreams setting defaults to Integer.MAX_VALUE, and the library provides no API to modify this threshold.
An unauthenticated remote attacker can exploit this by establishing a SPDY connection and initiating a flood of SYN_STREAM frames with the FLAG_FIN flag set to 0. Because the handler does not bound these streams, each request forces the application to allocate memory on the JVM heap and in direct memory buffers. Sustained exploitation leads to memory exhaustion, triggering a java.lang.OutOfMemoryError and resulting in a denial of service (DoS) for the affected service. Given Netty's widespread use in high-performance networking applications, this vulnerability poses a significant risk to the availability of systems relying on the SPDY protocol.
Impact
Successful exploitation results in a complete denial of service for the targeted Netty-based application. Since the vulnerability resides within the low-level transport handler, an attacker can crash the JVM by sending specially crafted, resource-intensive SPDY control frames, potentially leading to widespread downtime for critical infrastructure components.
Recommendation
Detection and mitigation teams should prioritize identifying applications utilizing the SPDY protocol with vulnerable versions of the Netty framework.
- Inventory all Java applications utilizing the
io.netty:netty-codec-http2ornetty-alllibraries to identify instances where theSpdySessionHandleris enabled. - Implement monitoring for JVM memory usage, specifically tracking
java.lang.OutOfMemoryErrorexceptions that correlate with increased network traffic from external SPDY peers. - Patch applications to the version of Netty that introduces a configuration API or restrictive default for
localConcurrentStreamsas identified in official Netty security bulletins. - If patching is not immediately feasible, consider disabling SPDY support at the load balancer or reverse proxy level if the protocol is not strictly required for business operations.
Immediate actions
Inventory all Java applications utilizing Netty libraries for SPDY usage.
Mitigations
Upgrade to the version of Netty that restricts concurrent streams or disables SPDY.
CVE-2026-93488