Netty(io.netty:netty-codec-http)在 HttpServerCodec 中存在一个无限制的每连接队列增长漏洞。该编解码器会跟踪每个尚未回答的流水线请求的 HTTP 方法;前 32 个条目被打包到一个 long 类型变量中,但每新增一个条目都会被追加到 methodOverflowQueue(一个无大小限制且无拒绝机制的 ArrayDeque)。远程、未经身份验证的攻击者可以在单个连接上对 HTTP/1.1 请求进行流水线处理,同时在自己的端阻止读取操作(从而防止响应被刷新),导致该队列无
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100655 | 7.5 HIGH | Netty before 4.1.138.Final Denial of Service via SpdySessionHandler |
| CVE-2026-100663 | 7.5 HIGH | Netty HTTP/1 CONNECT authority-form mistranslated to malformed HTTP/3 |
| CVE-2026-100661 | 7.5 HIGH | Netty HTTP/3 QPACK Prefixed Integer DoS via Unbounded Accumulation |
| CVE-2026-100660 | 7.5 HIGH | Netty before 4.2.18.Final QpackEncoder Unbounded Memory Retention |
| CVE-2026-100665 | 7.5 HIGH | Netty 4.2.11 through 4.2.17 QUIC Hostname Verification Bypass |
| CVE-2026-100662 | 7.5 HIGH | Netty HTTP/3 QPACK encoder-stream unbounded memory exhaustion DoS |
| CVE-2026-100664 | 7.5 HIGH | Netty 4.2.2 through 4.2.17 HTTP/1 Host Header Authority Confusion |
| CVE-2026-100657 | 7.5 HIGH | Netty before 4.1.138.Final ByteBuf Leak in StompSubframeDecoder |
| CVE-2026-100666 | 7.3 HIGH | Netty 4.2.0 through 4.2.16 Response Desynchronization via HttpServerCodec |
| CVE-2026-100659 | 6.5 MEDIUM | Netty 4.2.0 through 4.2.17 HTTP/3 Request Routing Bypass |
| CVE-2026-100658 | 5.3 MEDIUM | Netty before 4.1.138.Final Denial of Service via WebSocketServerExtensionHandler |
No comments yet