{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/netty-codec-compression--4.2.0.final--4.2.16.final/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["netty-codec-compression (\u003e= 4.2.0.Final, \u003c 4.2.16.Final)","netty-codec (\u003c 4.1.136.Final)"],"_cs_severities":["medium"],"_cs_tags":["denial-of-service","vulnerability","netty"],"_cs_type":"advisory","_cs_vendors":["Netty"],"content_html":"\u003cp\u003eA high-severity denial-of-service (DoS) vulnerability, tracked as CVE-2026-59901, has been discovered in the \u003ccode\u003eBzip2Decoder\u003c/code\u003e handler of the Netty networking framework. Specifically, the vulnerability affects the \u003ccode\u003enetty-codec-compression\u003c/code\u003e library (versions \u0026gt;= 4.2.0.Final, \u0026lt; 4.2.16.Final) and the \u003ccode\u003enetty-codec\u003c/code\u003e library (versions \u0026lt; 4.1.136.Final). This flaw allows a remote attacker to trigger an infinite loop within the run-length encoding (RLE) state machine of the \u003ccode\u003eBzip2BlockDecompressor.read()\u003c/code\u003e method by supplying a malformed bzip2 compressed stream. When exploited, the infinite loop permanently consumes the application's event-loop thread, rendering the affected Netty-based application unresponsive and causing a denial of service. This vulnerability impacts any application using the affected Netty versions for bzip2 decompression, making prompt patching critical to maintain service availability.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker identifies a target application utilizing vulnerable Netty versions (e.g., \u003ccode\u003enetty-codec-compression\u003c/code\u003e \u0026gt;= 4.2.0.Final, \u0026lt; 4.2.16.Final or \u003ccode\u003enetty-codec\u003c/code\u003e \u0026lt; 4.1.136.Final).\u003c/li\u003e\n\u003cli\u003eThe attacker determines that the target application processes bzip2 compressed data inputs.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a specially malformed bzip2 stream designed to specifically trigger an edge case in the run-length encoding (RLE) state machine.\u003c/li\u003e\n\u003cli\u003eThe crafted malformed bzip2 stream is transmitted to the vulnerable application through its expected input mechanism (e.g., as part of an HTTP request payload, a file upload, or a message in a queue).\u003c/li\u003e\n\u003cli\u003eThe Netty application receives the input and attempts to process the bzip2 compressed data using its \u003ccode\u003eBzip2Decoder\u003c/code\u003e handler.\u003c/li\u003e\n\u003cli\u003eDuring the decompression process, the \u003ccode\u003eBzip2Decoder\u003c/code\u003e handler invokes the \u003ccode\u003eBzip2BlockDecompressor.read()\u003c/code\u003e method to handle the incoming stream.\u003c/li\u003e\n\u003cli\u003eThe malformed bzip2 data causes the RLE state machine within \u003ccode\u003eBzip2BlockDecompressor.read()\u003c/code\u003e to enter an infinite loop.\u003c/li\u003e\n\u003cli\u003eThe event-loop thread responsible for processing the input becomes permanently tied up in this loop, causing the application to hang indefinitely and cease responding to further requests, achieving a denial of service.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-59901 leads to a complete denial of service for any application using the vulnerable Netty components. This means the affected application will become unresponsive, unable to process new requests or maintain existing connections, effectively bringing down the service. While specific victim counts are not available, given Netty's widespread use in Java-based applications, a significant number of services could be at risk if not patched. The primary consequence is service unavailability, which can lead to significant operational disruptions, financial losses, and reputational damage depending on the critical nature of the affected service.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-59901 immediately by upgrading \u003ccode\u003enetty-codec-compression\u003c/code\u003e to version \u003ccode\u003e4.2.16.Final\u003c/code\u003e or newer.\u003c/li\u003e\n\u003cli\u003ePatch CVE-2026-59901 immediately by upgrading \u003ccode\u003enetty-codec\u003c/code\u003e to version \u003ccode\u003e4.1.136.Final\u003c/code\u003e or newer.\u003c/li\u003e\n\u003cli\u003eReview applications for the presence of affected Netty versions listed in the \u0026quot;Affected Products\u0026quot; section that handle bzip2 compressed data.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-22T21:52:22Z","date_published":"2026-07-22T21:52:22Z","id":"https://feed.craftedsignal.io/briefs/2026-07-netty-bzip2decoder-infinite-loop/","summary":"A denial-of-service vulnerability exists in the `Bzip2Decoder` handler within Netty's `netty-codec-compression` and `netty-codec` libraries, allowing a remote attacker to exploit CVE-2026-59901 by providing a specially crafted bzip2 stream, which causes an infinite loop in the run-length encoding state machine, leading to the permanent hang of an event-loop thread and application denial of service.","title":"Netty Bzip2Decoder Infinite Loop Vulnerability Leads to Event-Loop Thread Hang (CVE-2026-59901)","url":"https://feed.craftedsignal.io/briefs/2026-07-netty-bzip2decoder-infinite-loop/"}],"language":"en","title":"CraftedSignal Threat Feed - Netty-Codec-Compression (\u003e= 4.2.0.Final, \u003c 4.2.16.Final)","version":"https://jsonfeed.org/version/1.1"}