Netty(io.netty:netty-codec-http)4.1.137.Final 及更早版本,以及 4.2.0.Final 到 4.2.17.Final 版本存在一个安全漏洞,该漏洞允许远程发起的 SPDY 流不受并发数量限制。具体而言,SpdySessionHandler 将 localConcurrentStreams 默认值设置为 Integer.MAX_VALUE,并且未提供任何 API 来修改这一限制。攻击者可通过建立 SPDY 连接并发送数百万个 FLAG_FIN=0 的 SYN_STREAM
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100663 | 7.5 HIGH | Netty HTTP/1 CONNECT authority-form mistranslated to malformed HTTP/3 |
| CVE-2026-100656 | 7.5 HIGH | Netty HttpServerCodec Unbounded Queue Growth via HTTP/1.1 Pipelining |
| CVE-2026-100661 | 7.5 HIGH | Netty HTTP/3 QPACK Prefixed Integer DoS via Unbounded Accumulation |
| CVE-2026-100660 | 7.5 HIGH | Netty before 4.2.18.Final QpackEncoder Unbounded Memory Retention |
| CVE-2026-100665 | 7.5 HIGH | Netty 4.2.11 through 4.2.17 QUIC Hostname Verification Bypass |
| CVE-2026-100662 | 7.5 HIGH | Netty HTTP/3 QPACK encoder-stream unbounded memory exhaustion DoS |
| CVE-2026-100664 | 7.5 HIGH | Netty 4.2.2 through 4.2.17 HTTP/1 Host Header Authority Confusion |
| CVE-2026-100657 | 7.5 HIGH | Netty before 4.1.138.Final ByteBuf Leak in StompSubframeDecoder |
| CVE-2026-100666 | 7.3 HIGH | Netty 4.2.0 through 4.2.16 Response Desynchronization via HttpServerCodec |
| CVE-2026-100659 | 6.5 MEDIUM | Netty 4.2.0 through 4.2.17 HTTP/3 Request Routing Bypass |
| CVE-2026-100658 | 5.3 MEDIUM | Netty before 4.1.138.Final Denial of Service via WebSocketServerExtensionHandler |
No comments yet