CPE
low
advisory
Netty HTTP/2 Decompressor Direct Memory Leak
1 CVEA vulnerability in Netty's HTTP/2 decompressor allows an unauthenticated attacker to trigger an uncontrolled memory leak leading to a JVM OutOfMemoryError via crafted HTTP/2 DATA frames.
netty-codec-http2 +1
denial-of-service
memory-leak
netty
cve-2026-56819
1c
medium
advisory
Netty SPDY SETTINGS Frame Denial of Service Vulnerability
3 TTPs 1 CVE 1 IOCA high-severity vulnerability, CVE-2026-55831, in Netty's SPDY SETTINGS decoder allows a remote unauthenticated attacker to trigger a denial of service by sending a crafted SPDY/3.1 SETTINGS frame that leads to excessive heap growth and CPU consumption due to unbounded map entries in `DefaultSpdySettingsFrame`.
netty-codec-http +3
denial-of-service
vulnerability
netty
spdy
java
memory-leak
DoS
3t
1c
1i