{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/netty-codec-http--4.1.137.final-4.2.0.final---4.2.17.final/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-100655"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["netty-codec-http (\u003c= 4.1.137.Final, 4.2.0.Final - 4.2.17.Final)","netty-codec-http (4.2.0.Final \u003c= 4.2.16.Final, \u003c= 4.1.136.Final)"],"_cs_severities":["high"],"_cs_tags":["denial-of-service","vulnerability","java"],"_cs_type":"advisory","_cs_vendors":["Netty"],"content_html":"\u003cp\u003eNetty (io.netty:netty-codec-http) versions up to and including 4.1.137.Final and from 4.2.0.Final through 4.2.17.Final contain a vulnerability in the SpdySessionHandler component. The handler defaults the maximum number of local concurrent streams to Integer.MAX_VALUE and lacks an API to override this limit. An attacker can initiate a SPDY connection and flood the target server with a high volume of SYN_STREAM frames where the FLAG_FIN bit is set to zero. This forces the server to allocate unbounded heap and direct memory to maintain the session state, eventually exhausting available system memory and triggering a JVM OutOfMemoryError. This leads to a complete service disruption for any application utilizing the affected Netty codec. The vulnerability is addressed in versions 4.1.138.Final and 4.2.18.Final.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a persistent denial-of-service condition affecting any Java application relying on the affected Netty codec for SPDY protocol support. This can lead to service downtime for critical infrastructure, APIs, and microservices. The impact is significant for organizations providing high-availability services where memory exhaustion leads to application crashes or service instability.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the Netty (io.netty:netty-codec-http) library to version 4.1.138.Final or 4.2.18.Final immediately to resolve CVE-2026-100655.\u003c/li\u003e\n\u003cli\u003eReview network infrastructure logs to identify anomalous spikes in SPDY traffic or sustained connections from single remote peers that do not terminate streams.\u003c/li\u003e\n\u003cli\u003eIf immediate patching is not possible, implement network-level rate limiting or SPDY protocol inspection to block traffic from unverified sources attempting to establish an excessive number of concurrent streams.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-26T17:00:14Z","date_published":"2026-09-26T15:06:56Z","id":"https://feed.craftedsignal.io/briefs/2026-09-netty-dos/","summary":"A memory exhaustion vulnerability in Netty's SpdySessionHandler allows remote attackers to trigger JVM OutOfMemoryErrors via unbounded concurrent SPDY stream allocation.","title":"Denial-of-Service Vulnerability in Netty io.netty:netty-codec-http","url":"https://feed.craftedsignal.io/briefs/2026-09-netty-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Netty-Codec-Http (\u003c= 4.1.137.Final, 4.2.0.Final - 4.2.17.Final)","version":"https://jsonfeed.org/version/1.1"}